正在加载价格
Back to blog

2026年9月28日 · 9 min read

The Bitget Hack and the Fragility of Crypto Custody

Bitget disclosed a $387.5 million breach that hit hot and warm wallets through forged withdrawal approvals, exposing critical gaps in custody controls and refuge in a user protection fund. The incident underscores how centralized exchange infrastructures—especially approval and back-end systems—can be exploited even when private keys remain safe, linking liquidity, custody, and operational trust in a single failure.

The most important crypto story today is not whether Bitcoin gets to $200,000 before Litecoin gets to $500, or whether another presale can manufacture demand with a triple-digit APY. It is the reported $387.5 million theft from Bitget, because it goes directly to the part of the market that still matters most: custody, liquidity control, and operational trust.

According to Bitget, the attack hit hot and warm wallets, while cold wallets and private keys were not compromised. That sounds reassuring until you look at the alleged failure mode. The company has described forged transfer approvals inside a backend wallet system. If that is accurate, this was not merely a “key theft” problem. It was a control-plane problem. In practice, a system that can authorize withdrawals without stealing keys is still part of the key path.

Bitget has pointed to North Korea-linked actors, reportedly citing IP addresses and VPN infrastructure associated with prior DPRK hacking activity. That may turn out to be right. Lazarus-style crypto theft is not theoretical, and past incidents have shown that state-linked groups understand exchange operations, laundering routes, and response windows. But attribution is not the strongest public evidence here. The strongest signal is the mechanism: a centralized exchange lost control of withdrawal authorization, attackers moved fast, and liquid on-chain markets did exactly what liquid on-chain markets do.

That is the uncomfortable part. Crypto’s liquidity infrastructure is now deep enough to absorb rapid laundering attempts, but many custody and approval systems remain opaque, centralized, and weakly auditable from the outside.

The Important Detail Is Not Just Who Did It, But How

Bitget says the stolen assets included major liquid tokens across multiple chains, including ETH, XRP, USDT, USDC, Avalanche, and BNB, with affected networks reportedly including Ethereum, XRP Ledger, Avalanche, BSC, and Arbitrum. The company temporarily froze withdrawals, kept deposits and trading open, and said its user protection fund, reportedly above $464 million at the time of the attack, would cover losses.

Those are the headline facts. The missing facts are more important for anyone managing risk.

There are no public transaction hashes in the reporting. No attacker address set. No full chain-by-chain asset breakdown. No independent forensic report. No published indicators of compromise. No detailed technical postmortem explaining which internal service accepted forged approvals, which credentials or systems were abused, or why existing limits did not stop the outflow.

That makes the incident simultaneously important and under-verifiable. Bitget’s statements provide useful operational signals, but they do not yet let users, counterparties, or other exchanges independently trace the funds or evaluate the actual scope of the failure.

The claim that private keys were not stolen should not be treated as a clean bill of health. For an exchange, the security model is not only “were the keys extracted?” It is also:

  • Who can initiate a withdrawal?
  • Who can approve it?
  • What systems validate destination, size, timing, and chain?
  • What limits exist per asset and per wallet?
  • Can an internal approval object be forged?
  • Are approvals independently verified before signing?
  • Are anomalous withdrawals blocked automatically or only detected afterward?

If forged backend approvals were enough to move hundreds of millions, then the private keys may have remained technically safe while the operational authority around them failed.

That distinction matters because most centralized exchange users are not underwriting cryptographic custody. They are underwriting an institution’s internal controls.

Liquidity Was Part of the Attack Surface

The reported laundering behavior is also instructive. Attackers allegedly swapped stablecoins and tokenized assets into ETH quickly through decentralized exchanges, while fragmenting native assets across many wallets.

That is rational attacker behavior. Stablecoins are liquid, but they are also issuer-controlled. USDT and USDC can be frozen at the contract or issuer level if addresses are identified quickly enough. ETH is not centrally freezable in the same way. Moving from stablecoins into ETH trades freeze risk for price/slippage risk. If liquidity is deep enough, that trade is worth making.

This is where crypto’s neutrality becomes a double-edged mechanism. AMMs and DEX aggregators do not know or care why an address is swapping. Liquidity providers earn fees. Arbitrageurs rebalance pools. The system processes transactions. That is the point of permissionless markets, but it also means response time matters enormously after a custodial breach.

Once stolen assets enter deep, composable liquidity, recovery becomes a race between:

  1. attacker fragmentation and conversion,
  2. exchange and issuer freeze requests,
  3. chain analytics labeling,
  4. centralized exchange deposit monitoring,
  5. law enforcement coordination.

Bitget reportedly offered a recovery bounty of up to 5%. That can help if funds touch identifiable custodians or cooperative infrastructure. But a bounty is not a security control. It is a post-failure incentive.

The lesson is not that DEX liquidity is bad. The lesson is that exchanges holding large amounts of user assets must assume public liquidity will be available to attackers within minutes. Hot and warm wallet policy has to be designed for that reality.

The Protection Fund Is a Promise Until Its Composition Is Known

Bitget’s user protection fund is central to the market impact of this incident. The company says the fund can cover the loss. On the surface, a fund above $464 million against a $387.5 million loss provides nominal coverage.

But nominal coverage is not the same as immediate, liquid, enforceable coverage.

The relevant questions are basic:

  • What assets make up the fund?
  • Are they cash, stablecoins, BTC, exchange tokens, or other volatile assets?
  • Where are they custodied?
  • Are they segregated from operating capital?
  • Are there liabilities or claims against them?
  • How quickly can they be deployed without causing additional market impact?
  • What remains after a near-$400 million reimbursement?

A protection fund that works is useful. A protection fund that is mostly a dashboard number is marketing. The public reporting does not yet provide enough detail to decide which one this is.

The staged withdrawal restoration beginning around September 28 is therefore not just an operational detail. It is a live trust test. If users are made whole and withdrawals resume cleanly, Bitget reduces immediate contagion risk. If withdrawal demand overwhelms liquidity, or if reimbursement details remain vague, the fund becomes less of a backstop and more of a confidence instrument.

In crypto, solvency is often not tested by accounting statements. It is tested by withdrawals.

Attribution Matters, But Verification Matters More

North Korea attribution will attract the most attention, and for understandable reasons. DPRK-linked groups have been tied by U.S. agencies and blockchain intelligence firms to large crypto thefts, including the previously reported Bybit incident in 2025. TRM Labs and others have repeatedly highlighted the scale of North Korean crypto hacking activity.

Still, public attribution should not be treated as complete simply because it is plausible.

The reporting cites IP and VPN patterns said to match prior DPRK infrastructure. That is a lead, not a full public proof package. VPN reuse can be meaningful in a broader forensic chain, but by itself it is not enough for outside observers to verify state sponsorship. Proper attribution usually requires a combination of infrastructure, malware/tooling overlap, operational patterns, wallet behavior, laundering paths, and sometimes intelligence not available publicly.

For market participants, the more urgent need is not a geopolitical label. It is actionable forensic data.

Other exchanges need addresses to block deposits. Stablecoin issuers need addresses to evaluate freezes. OTC desks and custodians need risk markers. Users need to know whether the loss is contained. Regulators need a technical explanation of the control failure.

“Very likely Lazarus” is less useful operationally than a signed incident report with transaction hashes, wallet clusters, chain paths, internal timeline, and remediation steps.

This Is the Same Market That Wants Mainstream Adoption

The timing is useful because the rest of the day’s crypto news points in the opposite direction: more adoption, more institutional flows, more payment integration, more speculative fundraising.

Bitcoin market commentary is focused on a 42% quarterly rally, reported ETF inflows, and MicroStrategy buying another 950 BTC around $79,670. That is a real demand channel, though still one that depends on continued external inflows rather than protocol cash flow. Litecoin-versus-Bitcoin target articles reduce the market to price arithmetic: how much percentage upside, how much market cap expansion, how much momentum extrapolation. Fine as a back-of-envelope exercise, weak as an allocation framework.

On the payments side, Mastercard’s UAE SME survey claims 14% of small and medium-sized businesses accept crypto and 10% pay business expenses in stablecoins. That is interesting if true, but it is survey data, not settlement data. Without volumes, partner names, stablecoin types, acquirer details, or recurring transaction metrics, it tells us more about willingness and positioning than actual payment infrastructure.

Then there is the usual presale noise. The TechBullion piece around Pepeto reads more like promotion than reporting: claimed swap, bridge, AI scanner, SolidProof audit, KYC, $11 million-plus presale, and 162% APY, but no contract addresses, no audit link, no vesting table, no revenue model, and no proof that “zero-fee” tools create value for token holders. That is not infrastructure. That is incentive packaging.

These stories look unrelated, but structurally they are connected. Crypto wants institutional capital, merchant adoption, deeper liquidity, and more accessible products. But every increase in liquidity and accessibility raises the cost of weak custody. The same rails that make onboarding easier make extraction faster when controls fail.

A market cannot keep celebrating liquidity when it pumps prices and pretending liquidity is an externality when it accelerates laundering.

What Serious Operators Should Watch Next

The Bitget incident should be judged by what becomes public over the next few days, not by the first attribution headline.

The key items to watch are straightforward: attacker wallet addresses, transaction hashes, asset-by-asset breakdown, independent forensic confirmation, stablecoin freeze actions, centralized exchange deposit attempts, law enforcement statements, and a technical postmortem explaining the forged approval path. Bitget should also disclose the composition and custody structure of its protection fund if it wants the market to treat reimbursement claims as more than corporate reassurance.

For builders, the lesson is operational. If your system can move funds, it needs defense in depth around approvals, limits, anomaly detection, and independent verification. “Cold wallets were safe” is not enough if warm-wallet authority can be tricked at scale.

For investors, the lesson is simpler: liquidity and adoption are not substitutes for controls. ETF inflows, merchant surveys, exchange listings, and presale numbers can all create the appearance of market progress. But the market’s real maturity is tested when something breaks, funds move, and everyone has to prove what they actually control.

Sources

Stan At, 4teen Founder