← Back to Daily Briefing (#CryptoHack)

Bitget Hot Wallet Compromise: $351.6M Stolen

Published September 25, 2026

On September 12, 2026, the Bitget cryptocurrency exchange suffered a major hot wallet breach, resulting in the theft of approximately $351.6 million (120,000 ETH and 6,000 BTC). The attack exploited a compromised backend Node.js signing script, backend/signing_service.js, which exfiltrated private keys to a Lazarus Group-linked C2 server at 185.141.63.122. Attackers utilized these keys to forge unauthorized withdrawal transactions. Bitget mitigated the immediate impact by suspending services and utilizing its insurance fund to cover losses. Remediation included upgrading to hardware security modules (HSMs) and implementing enhanced multisignature controls to secure custodial assets.

  • Incident Overview: Breach Details
  • Detected Sept 12, 2026, via anomalous large-value outflows on Ethereum and Bitcoin blockchains.
  • Total losses estimated at $351.6M, specifically involving ~120k ETH and ~6k BTC.
  • Assets were transferred from primary hot wallets to a series of newly created, attacker-controlled addresses.

  • Attack Vector: Backend Exploitation

  • Unauthorized modification of the backend/signing_service.js Node.js routine enabled private key exfiltration.
  • Stolen key material was transmitted to a command-and-control (C2) server at IP 185.141.63.122.
  • Attackers bypassed withdrawal logic by using the exfiltrated keys to sign and broadcast fraudulent transactions directly.

  • Threat Attribution: Lazarus Group

  • On-chain forensic analysis ties the outflow addresses to known Lazarus Group Ethereum and Bitcoin wallets.
  • The C2 infrastructure (185.141.63.122) is associated with prior North Korean state-sponsored cyber operations.
  • Attack demonstrates high sophistication by targeting specific exchange-side backend signing workflows.

  • Response & Technical Remediation

  • Bitget suspended all deposits and withdrawals to contain the outflow and initiate forensic investigations.
  • Financial impact was neutralized via the exchange's insurance fund, ensuring user asset protection.
  • Implemented mandatory hardware security module (HSM) usage and enhanced multisignature protocols for all hot wallet operations.

  • Market & Industry Impact

  • The Bitget token (BGB) experienced a ~12% price drop within 24 hours of the breach announcement.
  • The incident contributed to September 2026 being the highest month for recorded cryptocurrency exchange theft.
  • Highlighted the critical necessity of backend code integrity monitoring and hardware-based key storage.

Related posts

  1. Cybersecurity News — Bitget Hot Wallet Hacked – Attackers Stole $351.6 Million From Hot Wallets
  2. Bitcoinmagazine
  3. Coingabbar
  4. Altcoinbuzz
  5. Hackread
  6. Gulfnews
  7. Cyberkendra
  8. Tradingview
  9. Investing
  10. Cryptoslate
  11. Reddit

LINK COPIED TO CLIPBOARD