Trading
OrderbookOTC
RWA+
RWA & TradFiToken Planet
Insights
InsightsResearchLearnRWA LabAnnouncements
Custody
Login
Register
  1. Insights
  2. /
  3. Crypto & Digital Asset Research
  4. /
  5. Behind the Nearly US$400 Million Crypto Heist: What Was the Core Cause — and How Should Investors Protect Themselves?
Behind the Nearly US$400 Million Crypto Heist: What Was the Core Cause — and How Should Investors Protect Themselves?

Behind the Nearly US$400 Million Crypto Heist: What Was the Core Cause — and How Should Investors Protect Themselves?

At 18:31 UTC on 24 September 2026, Bitget’s security systems flagged unauthorised transfers leaving part of its hot and warm wallets. The first public figure was about US$351.6 million. The next day, after ZEC, TRX and other legs were added, the exchange revised the loss to about US$387.5 million; on-chain tallies cluster around US$388–390 million. That is the origin of the “nearly US$400 million” label. It is the largest single centralised-exchange theft of 2026 so far, and it helped make September one of the costliest months for crypto hacks this year.

Cold wallets were not touched. The exchange said customer losses fall inside a user protection fund of more than about US$464 million, and it has been reopening withdrawals in phases. Those remedies blunt the immediate fear that client assets simply vanished. They do not answer the sharper question: how did the funds leave while the keys were still in place and the process still looked legitimate?

What happened: probe the threshold, then exit across chains at once 

The public timeline shows a rehearsal, not a smash-and-grab. Around 18:31 UTC two test transfers left hot wallets — about 0.184 ETH and 193 TRX — both below the risk-control threshold, and neither tripped an alert. Roughly thirty minutes later the large drains began: one burst sent about US$87.6 million across five networks in about 15 seconds; another sent about US$202.8 million from warm wallets across five networks in about nine seconds. In a few dozen seconds, roughly three-quarters of the haul was gone.

The funds left on eight to nine networks, including Ethereum and EVM chains, the XRP Ledger and Tron. The basket included about 103 million XRP (worth about US$157 million at the time), plus ETH, USDT, USDC, ZEC and TRX. The attacker then converted freezeable stablecoins into ETH — the same “get off assets that an issuer can freeze at contract level” pattern seen in several large exchange thefts attributed to North Korea-linked actors. Bitget chief executive Gracy Chen said IP/VPN choices and on-chain behaviour were “highly consistent” with known DPRK-linked groups. Formal attribution is still pending.

The core cause: the keys held; the layer in front of the signer did not 

This is the sentence that matters. Chen has said the attackers did not forge customer withdrawal requests and did not obtain the private keys of the cold wallet or of any hot or warm wallet. They exploited a zero-day in a third-party security product used inside the exchange’s wallet infrastructure, obtained privileged internal credentials, and injected forged payout instructions into wallet back-end systems. Those instructions were treated as legitimate, entered the existing authorisation and signing flow, and were signed by Bitget’s own wallets.

Independent on-chain work matches that account. Outbound transactions used fee settings close to the exchange’s routine internal moves, but details such as gas limits did not match ordinary customer withdrawals. The wallets that signed were the exchange’s. The destination and amount fed to the signer came from an internal data source that had already been poisoned. For five years the industry hardened the key — HSMs, MPC, multisig, hardware devices. This time the attackers left the key alone and rewrote the ticket the key was asked to sign.

The core cause therefore sits in three layers, not in the slogan “we were hacked”:

  • Supply chain. A zero-day in a trusted third-party security component turned an external dependency into an internal admin door. A hardened wallet stack does not automatically offset a compromised tool the stack already trusts.
  • Authorisation semantics. The signing path checked that “this instruction arrived from our own back office,” but did not independently re-verify destination and amount against a source the same back office could not alter. Whoever owns the instruction source owns the withdrawal.
  • Risk thresholds. Small transfers under the alert line confirmed the pipe; only then came the multi-chain burst. Controls that score single-ticket size, and not “the same origin resonating across chains inside a short window,” treat the rehearsal as noise.

Stacked together, those three layers explain how “cold wallets untouched, keys intact” and “nearly US$400 million gone in hours” can both be true. The theft happened on the operational trust chain, not at the cryptographic layer.

What it means for the industry: the attack surface has moved from code to process 

The 2026 security map has a new centre of gravity. Losses from smart-contract bugs have fallen as a share of the total; infrastructure, supply-chain and social-engineering attacks have filled the gap. Read Liquid Network, protocol-layer incidents and this exchange theft together, and the common factor is not “another unaudited contract.” It is signing, caches, back offices and third-party tools becoming the new single points of failure. North Korea-linked actors already accounted for about 60% of global crypto theft in 2025. If this case is formally attributed, related thefts in 2026 may again cross the US$1 billion mark.

For licensed platforms the questions are institutional, not rhetorical. Are client assets segregated? Is hot-wallet exposure capped by policy? Must withdrawals be confirmed on a verification path isolated from the instruction source? After an incident, is there a compensation and disclosure arrangement that can be checked, not merely advertised? Hong Kong’s SFC VATP regime writes asset segregation, a compensation arrangement, risk disclosure and business resumption into licence conditions. That is not brochure language. It turns “what rights remain if the platform fails” from a verbal promise into an inspectable setup. When investors compare venues, the test is whether those arrangements can be independently verified — not the headline size of a protection fund.

How investors can reduce exposure: shrink the blast radius first 

No custody choice deletes risk. The workable goal is to make the upper bound of a single loss a number the holder can live with. Five executable rules follow from this case and from the structure of recent large thefts:

  • Keep only trading float on any centralised hot end. Medium- and long-term holdings belong in a hardware wallet the investor controls, or in a licensed arrangement with independent custody and asset segregation. An untouched cold wallet at the venue does not make the hot end a safe overnight box.
  • Ask about the signing path, not only whether multisig exists. Useful questions: does a large payout require a second confirmation independent of the wallet back office? Is there a timelock? If a third-party ops or security component fails, does the signer still take the ticket at face value? A venue that cannot answer has not made this layer visible to clients.
  • Test whether compensation can be verified. A protection fund, insurance policy or statutory compensation scheme should answer three questions: whose loss it covers, how long funding and pricing take, and whether the pot is segregated from operating cash. Coverage capacity is not the same as withdrawals remaining available under stress.
  • Treat the 72 hours after an incident as peak phishing season. Unsolicited “official support” messages, urgent links, and any page that asks for a seed phrase or 2FA code are not official channels. A legitimate platform will not request keys or seed phrases via a webpage or chat tool. Verify notices only on the official domain and authenticated social accounts.
  • Separate on-chain approvals from venue risk. If DeFi is in use, revoke unlimited allowances on a schedule and isolate large holdings from daily-driver wallets. Exchange incidents are routinely followed by clone sites and malicious approvals. Both perimeters have to be up at the same time.

For regulated investors in Hong Kong and the rest of Asia there is also an institutional choice: place assets that must be custodied on a platform that is SFC-supervised, segregates client assets, and publishes compensation and complaint arrangements — rather than treating trading depth as a proxy for custody safety. Depth answers whether an order can fill. Segregation and independent verification answer whether the asset is still there after something breaks.

Closing: the next one will not look like the last one 

Nearly US$400 million left because the signer trusted a poisoned internal instruction, not because the blockchain itself was broken. If the industry files this under the old heading of “sloppy hot-wallet management,” it will miss the shift that actually happened: attackers have moved from stealing the key to forging the ticket the key is asked to sign.

What an investor can control is not whether a given venue is the next target. It is how much of their own stack sits inside a radius where one back-office instruction is enough to authorise a payout. Narrow that radius, and the next headline is more likely to be someone else’s billions — not a zero in their own account.

About EX.IO Research 

EX.IO Research is the research arm of EX.IO, a Hong Kong SFC-licensed Virtual Asset Trading Platform. It publishes in-depth analysis on Bitcoin, stablecoins, real-world asset (RWA) tokenization, and virtual-asset regulation in Hong Kong and Asia. The mandate is benefit-first: state what an event means for the reader before recounting the news.

About EX.IO: EX.IO has been approved by the Securities and Futures Commission of Hong Kong (SFC) since December 2024 and is among the first virtual asset trading platforms (VATPs) admitted under the “deemed-to-be-licensed” regime of the Securities and Futures Ordinance and the Anti-Money Laundering and Counter-Terrorist Financing Ordinance.

Further reading (same research series) 

CLARITY Failed. Crypto Kept Climbing. The Rulebook Just Got Rewritten. https://www.ex.io/en/insights/category/research/clarity-failed-crypto-kept-climbing-the-rulebook-just-got-rewritten 

Related links 

Official website https://www.ex.io/ 

Insights https://www.ex.io/en/insights 

Research https://www.ex.io/en/insights/category/research 

Trading https://www.ex.io/en/trade 

RWA+ https://www.ex.io/en/rwa-market 

Disclaimer 

This article is prepared by EX.IO Research for general informational and educational purposes only. It does not constitute investment advice, an offer or solicitation, or a recommendation to buy, sell or hold any virtual asset or financial product. Virtual assets are highly volatile and involve a significant risk of loss, including possible loss of the entire amount invested. Readers should conduct their own independent research and, where appropriate, seek professional advice. EX.IO and its affiliates accept no liability for any loss arising from reliance on this article. Facts, figures and third-party statements cited herein are compiled from publicly available information as of the publication date, have not been independently verified in full, and may be revised as investigations continue. References to any platform, incident or product do not constitute an endorsement by EX.IO. 

© 2026 EX.IO | All Rights Reserved

View all posts

Latest

Behind the “Great Sell-Off” in Gold and Treasuries, a New Asset-Pricing Chain Is Quietly Taking Shape

Behind the “Great Sell-Off” in Gold and Treasuries, a New Asset-Pricing Chain Is Quietly Taking Shape 

Treasury Yields Keep Climbing, Yet Crypto Is “Steady with an Uptick”? Only Because a “Great Credit Questioning” Has Quietly Taken Shape

Treasury Yields Keep Climbing, Yet Crypto Is “Steady with an Uptick”? Only Because a “Great Credit Questioning” Has Quietly Taken Shape 

In a Compliant Era, How Can On-Chain Assets Earn Overnight Yield — and Be Deployed or Exited at Will?

 In a Compliant Era, How Can On-Chain Assets Earn Overnight Yield — and Be Deployed or Exited at Will? 

About
About Us
Our Team
On-Platform Trading Rules
Off-Platform Trading Rules
Trading Pairs
Fee Schedule
Token Admission and Removal Rules
Careers
Support
Support center
FAQ
API
Contact Us
Insights
Research
Learn
Announcements
Legal
Product Disclosure
Privacy Policy
Risk Disclosure Statement
Terms and Conditions
Compensation Arrangement
Business Resumption Plan
Complaint Handling Procedure
Community
Cert number: 25/18017
© 2026 EX.IO | All Rights Reserved