Chen: Bitget attacker ran sub-threshold test transfers before ~$361M drain wave

By Crypto Wire
September 28, 2026

Bitget’s Monday reopen now has a minute-by-minute attack clock. In an interview with The Block, timestamped about 11:30 a.m. EDT (15:30 UTC) September 28, CEO Gracy Chen says the attacker ran two small test transfers half an hour before the main drain—both below Bitget’s risk-control threshold—then pushed larger fraudulent withdrawals after already inserting commands through a third-party security product zero-day. This UPDATE links the AMA throughput chapter (9916) rather than silent-editing that URL.

What Chen timed. She told The Block the first unauthorized transfers hit at 6:31 p.m. UTC September 24: 0.184 ETH from an Ethereum hot wallet and 193 TRX from a Tron hot wallet. Both sat under the exchange’s risk-control threshold and triggered no system alerts. About thirty minutes later, larger transfers began. Chen said 17 transactions across Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism, and Avalanche between 6:58 p.m. and 8:09 p.m. UTC totaled about $361 million. Bitget’s reconciliation system flagged a significant discrepancy within seven minutes of the first large transfer—at 7:05 p.m. UTC—and its risk system blocked platform-wide user-initiated withdrawals, she said.

How access worked, per the interview. Chen reiterated that the attacker exploited a zero-day in a third-party security product to reach an internal management system, then inserted fraudulent withdrawal commands into wallet-related backend systems so they were treated as legitimate. The attacker deleted traces of those commands afterward—what Chen called “the trickiest part” of reconstructing the path. Private keys and cold wallets were not compromised, Bitget has said. The exchange is working with Mandiant and SlowMist and expects a formal incident report this week; on attribution, Chen said it is “still the same group of people that we suspect,” declining to name them until that report lands.



Balance-sheet and reopen context in the same interview. Bitget’s user protection fund, worth $465 million on September 25, will absorb the roughly $388 million loss, Chen said, and will be replenished to at least $300 million within a week from corporate reserves that stood above $1.4 billion as of an August 31 audit. “An incident like this scale is very serious,” she said. “But serious doesn’t mean existential.” On the reopen tape, The Block notes BTC withdrawals resumed Monday and processed more than 3,000 BTC in the first hour, with ETH withdrawals still set for September 29—alongside the AMA’s later ~4,098 BTC / 9,585-order processing print in 9916.

How this differs from prior chapters. 9908 carried The Block’s method statement pinning the exploit on a third-party security product as BTC reopen began. 9916 quantified Chen’s AMA throughput and BSC BTC restore. Trail LNs (9939, 9969, 9976) cover THORChain swaps, ZachXBT Discord aliases, and the ~$678 million two-day volume print—fund hops, not the exchange’s internal clock. Today’s new facts are Chen’s The Block interview timeline: sub-threshold 0.184 ETH / 193 TRX probes at 18:31 UTC, the 17-transfer ~$361 million wave, seven-minute reconciliation at 19:05 UTC, trace deletion, fund replenish-to-$300 million, and first-hour 3,000+ BTC processing. Do not invent that the desk verified the risk-threshold number independently, that cold wallets were hit, or that the incident report already named a group.

What to watch on-chain next: the Mandiant/SlowMist incident report Chen flagged for this week, whether ETH withdrawals open on the September 29 window without a second drain signature, and whether the same alias cluster ZachXBT mapped keeps moving Bitget-trail funds through THORChain after the refuse-service fight.

Bottom line: Chen tells The Block the Bitget attacker probed with two sub-threshold test transfers at 18:31 UTC September 24 before a ~$361 million multi-chain wave—while the protection fund absorbs the loss and aims to refill to at least $300 million—Rug Room UPDATE after 9916.

Disclaimer: This article is provided for informational and educational purposes only. It does not constitute financial, investment, legal, or trading advice. The NFT market is highly volatile, and past performance is not indicative of future results. Readers should conduct their own research and consult qualified professionals before making any decisions related to digital assets. The cover image for this article may have been created using artificial intelligence (AI).

8bitcrypto NewsDesk

Crypto Wire — she runs the default news desk from Los Angeles. Market tape, NFT drops, and policy wires filed fast with zero shill. Your straight signal from 8bitcrypto.

One thought on “Chen: Bitget attacker ran sub-threshold test transfers before ~$361M drain wave”

Leave a Reply

Discover more from 8bitcrypto

Subscribe now to keep reading and get access to the full archive.

Continue reading