0x573f199f573f…573f19a2
Bitget Sees $463M Outflow Day After $388M Hot Wallet Hack
Bitget bled $463M in a single day after hackers stole up to $388M via a third-party security flaw, draining its User Protection Fund below $200M as Mandiant probes a Lazarus link.

Outputs
Bitget recorded $463M in net outflows on September 29, the largest single-day withdrawal tracked by DefiLlama in four years.
The September 24 hack exploited a third-party security product to spoof transaction data; losses are now estimated at $387.5M–$388M.
The User Protection Fund fell from over $464M to below $200M; CEO Gracy Chen cited initial forensic indicators pointing to North Korea's Lazarus Group.
Crypto exchange Bitget recorded $463 million in net outflows on September 29, the largest single-day customer withdrawal event tracked by DefiLlama in four years, after attackers stole up to $388 million from the platform's hot wallets on September 24.
The revised loss estimate sits between $387.5 million and $388 million, up from the $351.6 million initially reported in the immediate aftermath of the breach. The attack exploited a vulnerability in a third-party security product that interfaced with Bitget's backend systems, allowing the attackers to inject spoofed transaction data into the exchange's authorization process.
Bitget's private keys were never compromised, and cold storage wallets remained untouched throughout the incident, according to the exchange's account of the breach. The vulnerability resided in the external security product, which let attackers craft transaction data that appeared legitimate to Bitget's authorization layer.
The attackers ran two smaller test transfers before executing the main unauthorized withdrawal, probing Bitget's risk controls. That reconnaissance pattern is consistent with tactics previously attributed to North Korean threat actors.
CEO Gracy Chen disclosed that initial forensic indicators point toward the Lazarus Group, the North Korea-linked hacking collective. Mandiant and SlowMist, two cybersecurity and blockchain forensics firms, are assisting with the ongoing investigation.
The balance sheet math
Bitget holds roughly $5.7 billion in reserves, meaning the hack represented approximately 6.8% of total holdings. The solvency question is less pressing than the operational one: the exchange built a User Protection Fund specifically for incidents of this kind, and that fund has now absorbed a substantial share of the damage.
Before the hack, the fund exceeded $464 million — roughly enough to cover the stolen amount in full. Post-incident, it has reportedly fallen below $200 million, implying at least $264 million deployed to cover user losses. The remaining gap between the fund's deployment and the total loss figure raises questions about how Bitget intends to make users whole beyond the reserve buffer.
The exchange initiated a phased resumption of withdrawals on September 28, four days after the breach. That timeline reflects the dual pressure exchanges face after an incident: reopening withdrawals quickly enough to prevent a credibility spiral, while verifying that the exploited pathway is fully closed.
The $463 million outflow on September 29 — a day after withdrawals resumed — suggests a significant cohort of users chose exit over reassurance, even with the protection fund backstopping losses. For an exchange in the world's top ten by trading volume, sustained net outflows at this scale would compound the direct hit from the theft itself, compressing the revenue base that funds reserve replenishment.
Third-party risk in focus
The operational detail most likely to draw scrutiny from other exchanges is the attack vector. Bitget's own custody practices held: private keys stayed secure and cold storage went untouched. The failure occurred in a third-party security product integrated with backend infrastructure — a supply-chain exposure that no amount of cold storage discipline can fully mitigate.
For an industry that has spent years hardening key management, the Bitget incident shifts attention to the integration layer between exchanges and their vendors. Authorization systems that trust data from external tooling represent a single point of failure that adversaries can target without ever touching the keys themselves.
What comes next
The Mandiant and SlowMist investigations will determine whether the Lazarus attribution hardens from initial indicator into confirmed conclusion, a finding that could trigger coordinated responses from law enforcement and blockchain-analytics firms to freeze the stolen funds across compliant venues.
Bitget, meanwhile, faces the slower task of rebuilding a protection fund that now sits below $200 million against a $5.7 billion reserve base, and of convincing the users who pulled $463 million in a single day that the third-party pathway behind the breach has been permanently closed.
via Crypto Briefing (Source)