NewsCryptoBitget Hacker Withdraws $1.23 Million From Binance, Routes Funds to Attacker-Controlled Wallet

Bitget Hacker Withdraws $1.23 Million From Binance, Routes Funds to Attacker-Controlled Wallet

Author: CryptoBriefing·

Key Takeaways

  • •The Bitget attacker withdrew $1.23 million from Binance and sent it to a wallet linked to the hack, following earlier withdrawals of ETH and roughly $545,000 in USDT from the exchange's hot wallets.
  • •The breach, detected on September 24 at 18:31 UTC, caused unauthorized transfers totaling up to $387.5 million, a figure revised upward from an initial estimate of $351.6 million.
  • •Rather than stealing private keys or breaching cold storage, the attacker compromised Bitget's backend system to spoof transaction data and trick the platform into authorizing illegitimate transfers.
  • •Stolen funds have been traced across Ethereum, BNB Chain, and TRON, and Bitget and Binance are working together with law enforcement, Mandiant, and SlowMist to investigate the case.
  • •Bitget paused withdrawals and pledged to cover customer losses through its User Protection Fund, which holds over $464 million, while unconfirmed speculation suggests possible North Korean involvement based on IP address patterns.
Bitget Hacker Withdraws $1.23 Million From Binance, Routes Funds to Attacker-Controlled Wallet

The attacker behind the large-scale Bitget security breach has begun moving stolen funds through Binance, withdrawing $1.23 million from the exchange and routing it to a wallet linked to the hack. The transaction marks a new phase in what has become one of the largest crypto heists of 2026, as investigators race to trace assets across multiple blockchain networks.

The original breach was detected on September 24 at 18:31 UTC and resulted in unauthorized transfers totaling as much as $387.5 million from Bitget's hot and warm wallets.

How the funds are moving

On September 25, just one day after the initial theft, on-chain analysis revealed five separate withdrawals from Binance's hot wallets, including approximately 88.35 ETH, 89.36 ETH, 79.93 ETH, and roughly $545,000 in USDT. By September 26, a total of 457.9 ETH had been forwarded to a wallet presumed to be under the attacker's control.

The latest $1.23 million withdrawal follows the same playbook: pull funds from a major exchange, then consolidate them in a wallet beyond the reach of any single platform's freeze capabilities. That pattern matters for the recovery effort, because centralized exchanges are typically where stolen funds are most exposed to intervention, since compliance teams can flag and freeze suspicious deposits, whereas assets moved into self-custody across multiple networks become far harder to intercept.

Blockchain analytics firms, including Bit, have traced stolen funds flowing across Ethereum, BNB Chain, and TRON — a spread that forces investigators to coordinate across separate networks with different tooling. Bitget and Binance have confirmed they are collaborating on tracing the stolen funds. Law enforcement agencies have also been notified, and cybersecurity firms Mandiant and SlowMist are both assisting in the investigation, a breadth of outside involvement that reflects the scale of the case.

Inside the breach

The attack itself was unusually sophisticated. Rather than stealing private keys or breaching cold storage, the attacker compromised Bitget's backend system in a way that allowed them to spoof transaction data, tricking the system into authorizing transfers that looked legitimate internally while actually routing funds to the attacker.

Initial loss estimates pegged the damage at $351.6 million, a figure later revised upward to $387.5 million as investigators identified additional unauthorized transfers. Bitget paused withdrawals shortly after the breach was detected and pledged to cover customer losses through its User Protection Fund, which holds over $464 million — a reserve larger than the revised loss total.

North Korea speculation and industry fallout

IP address patterns identified during the investigation have led some analysts to speculate that North Korean-linked actors may be behind the breach. This attribution has not been confirmed by authorities, but it would fit a well-documented pattern. North Korean hacking groups, particularly the Lazarus Group, have been linked to billions of dollars in crypto theft over the past several years, often using similarly sophisticated multi-chain laundering techniques. The closest precedent in scale is the February 2025 theft of roughly $1.5 billion from Bybit, which investigators attributed to North Korean-linked hackers. Whether authorities confirm or rule out the attribution, and whether more of the funds can be intercepted at centralized venues before reaching self-custody, are the open questions most likely to shape the case in the days ahead.