- The breach shifts attention from key custody to the integrity of the systems preparing transactions for authorization.
- Cross-chain asset movement turned a single exchange incident into a tracing challenge spanning multiple financial infrastructures.
- The case is reopening questions over where intervention is technically possible once stolen assets enter decentralized protocols.
The most revealing detail in Bitget’s security breach may be what the attacker apparently did not steal.
GoPlus Security says its investigation found no private-key leak. Instead, the security firm says attackers compromised a critical wallet backend, manipulated transaction data and caused Bitget’s authorized signing process to approve transfers the exchange never intended to make.
#THORChain has never been strictly decentralized@THORChain comparing itself to decentralized L1s like BTC and ETH does not hold. Do not enable criminals — or put the industry at risk — just to take swap fees on stolen funds.
1⃣ Custody: TSS vaults ≠ base-layer consensus… https://t.co/x23ZWABnNb pic.twitter.com/D3wD9qG3hX
— GoPlus Security (@GoPlusSecurity) September 27, 2026
That moves the security failure one step earlier than the key itself.
A protected private key can prevent an outsider from independently signing a transaction. It cannot solve the entire problem if compromised infrastructure is able to feed false instructions into an otherwise legitimate authorization process.
GoPlus says the largest burst moved roughly $185 million in about one minute, while the wider draining activity lasted around two hours and 25 minutes. Bitget has confirmed that attackers bypassed existing security controls, but it has not publicly disclosed enough technical detail to independently establish every element of GoPlus’s reconstruction.
A Valid Signature Can Still Approve the Wrong Transaction
Bitget detected unauthorized transfers from portions of its hot and warm wallet infrastructure at 18:31 UTC on September 24. Its cold wallets were not affected. The exchange initially estimated the loss at $351.6 million before raising the figure to approximately $387.5 million after incorporating Zcash and TRON transfers omitted from the first calculation. Bitget
GoPlus’s analysis focuses less on where the assets were stored and more on what happened before they moved.
Its reconstruction can be reduced to four stages:
- Compromised backend → forged transaction data → authorized signing process → unintended transfer
The distinction between key security and transaction integrity is crucial.
Cryptographic authorization proves that the required signing authority approved a transaction. An exchange still needs controls capable of determining whether the destination, amount and transaction payload presented for approval correspond to what its systems genuinely intended to execute.
GoPlus sees structural similarities with the 2025 Bybit breach, although that does not mean the two attacks used identical methods. Until Bitget releases a detailed technical post-mortem, claims about the precise compromised component or the role of particular HSM or MPC systems would go beyond the public evidence.
Bitget says it has now identified the attack path and underlying vulnerability, remediated the flaw and brought in Mandiant and SlowMist to support the continuing investigation.
Four Bitcoin Took a Much Longer Route
The theft itself happened quickly. Moving the proceeds presents a different problem.
AMLBot says it traced one relatively small branch of the stolen funds from a Bitget-linked TRON wallet into Wasabi CoinJoin.
Update: It seems stolen funds from the @bitget hack have started to be laundered through Wasabi CoinJoin (mixer)
Our tracing links ~4 BTC in a CoinJoin round back to a Bitget TRON wallet. The funds were swapped from TRX to USDT, bridged to Ethereum via @USDT0_to, swapped to ~145… https://t.co/8JBaoMM1xp pic.twitter.com/ncTVyeIT3S
— AMLBot (@AMLBotHQ) September 26, 2026
The path published by the blockchain analytics firm ran through several assets and networks:
- TRX → USDT → USDT0 → Ethereum → ~145 ETH → THORChain → ~4.59 BTC → Wasabi CoinJoin
AMLBot linked roughly 4 BTC inside one CoinJoin round back to the Bitget flow and said it had blacklisted associated addresses while monitoring the remaining Bitcoin for further activity. crypto.news
The route shows why tracing a major exchange theft becomes progressively more complicated after the first transfer.
An investigator is no longer following one token on one blockchain. The assets can be swapped, bridged to another network, converted again, routed through cross-chain liquidity and eventually enter privacy infrastructure.
CoinJoin combines Bitcoin inputs and outputs from multiple participants, making direct transaction relationships harder to determine. Its use is not itself evidence of criminal activity. In this case, the relevance comes specifically from AMLBot’s claim that funds associated with the Bitget theft entered a CoinJoin round.
And the amount traced there represents only a small piece of the incident.
AMLBot estimated that about $343 million remained dormant across 13 attacker wallets during its September 25 assessment. Pluang
THORChain Sits in the Most Contested Part of the Route
The appearance of THORChain between Ethereum and Bitcoin has reopened a dispute that goes beyond Bitget.
GoPlus challenged comparisons between THORChain and base-layer networks such as Bitcoin or Ethereum, arguing that their architectures provide different degrees of intervention.
Its criticism centers on THORChain’s threshold-signature vault architecture and existing mechanisms capable of pausing network functions or chain-specific signing. From those features, GoPlus argues that the protocol has greater capacity to intervene in illicit flows than a conventional base-layer validator or miner. Pluang
That argument should not be confused with an established conclusion that THORChain can simply blacklist any individual address.
Having emergency controls and being able to selectively reject particular transactions are different technical questions. There is also a governance question over who determines that funds should be blocked and what evidence should be required before intervention.
The Bitget trail makes that disagreement unusually concrete.
A single branch allegedly moved from a centralized exchange through stablecoins, a bridge, Ethereum, THORChain, Bitcoin and finally CoinJoin. Every layer has different operators, technical controls and assumptions about censorship.
The Missing Piece Is Bitget’s Full Technical Account
There is now substantial public evidence about where the money went, but less transparency about exactly how the attacker gained the ability to move it.
Bitget has published four primary attacker-controlled receiving addresses covering EVM networks, XRP Ledger, Zcash and TRON. The exchange says affected assets included XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX. Bitget
Those addresses give independent researchers concrete on-chain artifacts to follow.
The root cause is harder to verify externally.
Bitget says it knows the attack path and has fixed the vulnerability. GoPlus offers the more specific theory that attackers compromised the transaction-signing trust chain rather than stealing private keys.
A complete technical post-mortem would allow those two pieces to be reconciled and show precisely which controls failed.
Until then, the strongest lesson from the available evidence is narrower but more useful: securing a private key protects signing authority. Exchange security also has to protect the instructions that reach that authority.
The Bitget attacker may have demonstrated the difference in less than a minute.
Credit: Source link




