Fraudulent sites are impersonating Global Ledger
How to stay safe
Skip to content

The Bitget Hack: A $387.5M Theft and Laundering Breakdown

For Compliance Teams and Law Enforcement
Alesya Sypalo

Alesya Sypalo

Crypto Expert and PR Lead

October 01, 2026 7 min read

On September 24, 2026, around $387.5 million in crypto assets was transferred from Bitget to attacker-controlled addresses across multiple blockchains. Before the unauthorized transfers had stopped, the stolen funds were already being split across wallets, swapped into other assets and routed between chains.

What does this case show about how quickly stolen funds can begin moving — and how fast the trail can become harder to follow? 

This investigation reconstructs the first hours of the Bitget hack, follows the movement of the stolen funds and examines the most critical consequences for compliance teams and law enforcement.

Key Takeaways
  • ~$387.5 million was transferred to attacker-controlled addresses across Ethereum and several EVM networks, XRP Ledger, Zcash and TRON.

  • 21 identified theft transfers took place across eight blockchains over ~2 hours and 52 minutes.

  • Movement of the stolen funds began while the initial theft sequence was still underway.

  • By 14:34 UTC on September 25, 66 traced swaps involving stolen BNB and TRX had been completed for a total of 126.71 BTC.

  • On September 25, ~68,465 ETH remained across nine attacker-controlled wallets, while 98.34 million XRP was distributed across six accounts.

  • The case shows how quickly tracing becomes more difficult once stolen funds are split across wallets, swapped into other assets and moved across chains, making accurate labeling and attribution harder at every step.

 

What Happened? The General Chronology

On September 24, unauthorized transfers began moving assets from Bitget across multiple blockchains.

Bitget later said the attack involved a compromised backend wallet system and spoofed transaction data, while private keys and cold wallets were not compromised. Withdrawals were suspended following the attack.

The first estimate put the loss at $351.6 million. As investigators identified additional transfers, the total increased to around $387.5 million.

At around $387.5 million, the Bitget hack became one of the largest crypto thefts reported in 2026.

But the size of the loss is only part of what makes this case important for compliance teams and law enforcement.  

The funds began moving while the theft was still underway, giving investigators very little time before the trail started spreading across wallets, assets and blockchains.

The First Three Hours

The first several hours show how quickly the attack accelerated from small test transfers to coordinated activity across multiple chains:

  • 18:31 UTC — 93 TRX and 0.84 ETH were transferred 11 seconds apart.

  • Around 19:01 UTC — assets moved across five chains within about 15 seconds.

  • Around 19:16 UTC — another five-chain burst followed within nine seconds, including 91.4 million XRP.

  • 21:23 UTC — the unauthorized transfer sequence ended. In total, 21 theft transfers were identified across eight blockchains.

 

Laundering had already started before the unauthorized transfers ended.  

Funds were being split across wallets, swapped into other assets and moved between chains, making it harder to keep addresses accurately labelled and maintain attribution to the original hack. 

This is what makes the timeline important: the response window was already narrowing before the theft itself was over. By the final unauthorized transfer, investigators were dealing with a trail that was already changing in real time.

 

How the stolen funds moved further

Once the funds had left Bitget, two clear patterns emerged: part of the proceeds was swapped into BTC, while roughly $339 million remained in ETH and XRP across the initial attacker-controlled wallets.

Let's look at these two paths more precisely. 

1. Swapped into BTC

  • Around $6.3 million worth of ETH was swapped into BTC. By September 28, roughly 2,390 ETH had been exchanged for 75.2 BTC across 27 cross-chain swaps.

  • Stolen BNB and TRX worth about $10.6 million were swapped into BTC. By 14:34 UTC on September 25, Global Ledger had traced 66 swaps involving those assets, resulting in 126.71 BTC.

2. Remained in ETH and XRP

  • Around $184 million in ETH remained across nine attacker-controlled wallets. On September 25, those wallets held 68,465 ETH.

  • Around $154 million in XRP remained across six attacker-controlled accounts. On September 25, they collectively held 98.34 million XRP. By September 28, around 54 million XRP had been transferred out of the original accounts, while roughly $75 million worth of XRP remained there.

Native XRP cannot be frozen by Ripple; receiving exchanges can intervene when identifiable stolen funds reach their infrastructure.  

Bitget also asked THORChain to block hacker-linked addresses, but the protocol declined selective address blocking.

Read More

Laundering Speed: Lessons from 255 Hacks for VASPs

Read the full report

Why the Trail Becomes Harder to Follow

In the Bitget case, stolen funds began moving through new wallets, swaps and cross-chain routes almost immediately. Each new step added distance between the funds and the addresses directly linked to the hack.  

This creates a practical attribution problem.

A transaction can still be traced on-chain, but by the time the funds reach another service or exchange, the immediate counterparty may be several steps removed from the original theft.

Global Ledger’s High-Risk Benchmark report shows that average exposure depth increased from 1.51 blockchain hops in 2021 to 2.78 by 2023, then remained broadly stable.

That makes continuously updated attribution critical.

If the connection between a new wallet and the original hack is not preserved as the funds move, the transactions may remain visible on-chain while their link to the theft becomes progressively harder to recognize.

The Bitget hack shows how quickly this can happen within a single incident. Across centralized exchanges, the same problem exists at a much larger scale: billions in high-risk exposure arrive through routes of very different depth, complexity and traceability.

How much high-risk exposure do centralized exchanges face?

Global Ledger’s High-Risk Benchmark analyses $187.75 billion in high-risk exposure across 99 centralized exchanges, including exposure depth, risk categories, assets and jurisdictions.

Join the waiting list

 

Bitget Hack: Why It Matters

For Compliance Teams

The Bitget case shows how quickly a clearly attributable hack can become harder to recognize when the funds reach a centralized exchange or OTC provider. Within hours, stolen assets had moved through new wallets, swaps and cross-chain services.

Global Ledger’s Laundering Speed: Lessons from 255 Hacks for VASPs report found that once funds from a hacker-controlled address reach a VASP, compliance teams typically have only a 10–15-minute window to act.

That makes continuous monitoring and up-to-date attribution critical: the relevant risk signal may no longer be a direct transfer from a known hacker wallet, but exposure that has passed through multiple layers of intermediary wallets, swaps and cross-chain routing before reaching the platform.

For Law Enforcement

Centralized exchanges are one of the key chokepoints in a crypto investigation. Unlike non-custodial DEXs and cross-chain protocols, they can associate an on-chain transaction with a verified account holder, provide account and transaction records, and freeze funds before they are withdrawn.

That makes the route to a centralized platform especially important.

More sophisticated laundering often adds wallets, swaps, bridges and decentralized services before funds reach that point, delaying the moment when tracing can turn into identification, freezing and potential recovery. The faster investigators can preserve attribution across that route, the greater the chance of acting when the funds reach an intervention point.

Trace Stolen Funds Across Chains
and Preserve Attribution
in Real Time
Schedule a demo