The attacker behind the Bitget hack tested the exchange's risk controls with two small transfers before executing the $388 million drain. CEO Gracy Chen disclosed the reconnaissance on Saturday, four days after the September 24 breach.
At 6:31 p.m. UTC, the attacker moved 0.184 ETH from an Ethereum wallet and 193 TRX from a Tron wallet. Combined value: roughly $480.
Twenty-seven minutes later, at 6:58 p.m., the main attack began.
Seventeen transactions across five chains
Between 6:58 p.m. and 8:09 p.m., the attacker executed 17 larger withdrawals totaling about $361 million across multiple blockchains. Bitget's reconciliation system flagged the discrepancy at 7:05 p.m., seven minutes after the attack wave started. The platform blocked all withdrawals platform-wide at that point, but $388 million had already left.
The Bitget hack exploited a zero-day vulnerability in third-party security software to obtain valid admin credentials. The attacker injected fraudulent withdrawal commands into the wallet backend and deleted traces afterward. Private keys and cold wallets stayed untouched throughout the breach.
Protection fund covered losses, XRP portion unfroze-able
Bitget's user protection fund held $465 million before the attack. The exchange announced it would replenish the fund with $300 million within one week, bringing it to a post-incident balance lower than the amount stolen but sufficient for the stated coverage.
XRP made up $157 million of the total, split among five attacker accounts. About $83 million of that XRP moved out of three wallets by Saturday. The remaining $75 million sits in addresses that cannot be frozen under network rules. Ripple can freeze tokens it issues, but the XRP Ledger does not grant that authority over native XRP itself.
Circle and Tether froze roughly $320,000 in stablecoins tied to the breach. Their tokens include blacklist functions that XRP lacks.
Withdrawals resuming, North Korea attribution preliminary
Bitcoin withdrawals reopened Monday at 8 a.m. UTC. The exchange processed over 3,000 BTC in the first hour. Ethereum withdrawals across six chains and USDT withdrawals on four networks are scheduled to resume Sunday at 8 a.m. UTC. All remaining assets, fiat withdrawals, and peer-to-peer transactions are set to restore by October 2.
The Bitget hack prompted the exchange to launch a bounty offering 5% of successfully frozen or recovered funds. Security firms Mandiant and SlowMist are conducting independent forensic reviews, with a formal incident report expected this week.
Chen noted preliminary indicators suggesting a connection to a North Korean group, citing IP addresses and VPN patterns matching prior attacks, but emphasized the attribution remains unconfirmed pending the full investigation.