Logo

$350M Bitget Hot Wallet Drain: How Blockaid’s Cosigner and Onchain Monitoring Can Protect Exchange Hot Wallets

•Blog Post
Bitget 350m Incident Blockaid

Executive Summary:

On 24 September 2026, an attacker drained approximately $350M from Bitget's hot and warm wallets over several hours, moving funds across eight chains spanning Ethereum, Arbitrum, Base, Optimism, BSC, Avalanche, the XRP Ledger, and TRON. Bitget confirmed the unauthorized transfers, activated its emergency response team, and paused user withdrawals as a precaution while deposits and trading continued.

Blockaid's research team and AI investigation agents have been tracing the stolen funds since the first transfers, mapping them across all eight chains as the attacker converts and bridges the proceeds. Blockaid flagged the attacker's addresses as malicious, published the incident to the Blockaid ecosystem feed, alerted customers, and shared the addresses with the bridges, swap routers, and protocols on the laundering path so they can screen against them. Monitors on the attacker's wallets are tracking every hop as the funds move, and Blockaid is working with chain foundations and ecosystem partners as they respond to the contagion risk from this exploit.

This report covers how the attack unfolded, the response from Bitget and across the ecosystem, and where Blockaid would have helped to prevent and contain the incident It is written for exchanges, custodians, where the strongest fix is transaction validation that sits outside the systems an attacker can reach.


The Exploit: How it Unfolded

Bitget's full post mortem is pending, so the initial access path has not been disclosed. Based on Bitget's statements and Blockaid's tracing, the attack unfolded in five stages.

  1. Backend Compromise. According to Bitget's CEO, the attacker compromised a backend system that feeds transaction data to the signing process and used it to spoof that data, causing Bitget's own infrastructure to produce valid signatures for transfers the exchange never intended to make. Bitget has ruled out private key compromise.
  2. Staging. At 18:31 UTC on 24 September, the attacker's receiving address was funded with 0.84 ETH from one of Bitget's own compromised hot wallets, so the same infrastructure that would sign the drain also staged the attacker's address. Bitget's public notice puts its detection of unauthorized transfers at the same minute.
  3. The Drain. At 18:58 UTC, the first large transfer left a Bitget hot wallet, approximately $34.75M in USDT sent to the address funded 27 minutes earlier. Between 18:58 and 21:23 UTC, a window of two hours and 25 minutes, further transfers of ETH, USDT, USDC, AVAX, BNB, XAUt, XRP, and TRX left other Bitget wallets across multiple chains. The largest wave, roughly $185M, landed in about a minute at 19:16 UTC, spanning 13,966 ETH on Ethereum, roughly 91.4M XRP on the XRP Ledger, and 20.6M TRX on TRON.
  4. Conversion and Consolidation. From around 19:00 UTC, the attacker swapped stolen tokens into ETH through decentralized exchanges (DEXs) and bridged them to Ethereum mainnet, split across many smaller transactions. By roughly 22:00 UTC, the attacker had split the proceeds on Ethereum-compatible (EVM) chains, about $155M in ETH and AVAX, into dormant vaults.
  5. Cross-Chain Movement of Proceeds. Hours after the exploit, starting at approximately 02:13 UTC on 25 September, the XRP proceeds began moving through cross-chain swaps and bridges toward BTC and ETH. As of this update, only small amounts of XRP have moved this way, and the bulk of the stolen funds sits parked in the vaults and in XRP wallets that have not moved.

Context: Exchange Hot Wallets and Automated Signing

Exchanges hold customer funds across tiers of wallets. Cold wallets keep the bulk of reserves offline. Hot and warm wallets hold the liquidity that serves customer withdrawals, and because withdrawals run continuously, their signing is automated. A withdrawal request passes through the exchange's backend, where it is checked against balances and risk rules, and is then handed to the authorization process that produces the signature. Many exchanges secure signing authority through multi-party computation (MPC), where several parties each hold a share of the signing key, or with multisignature wallets that require several independent approvals.

That setup leaves two attack surfaces. One is the signing keys themselves, and the other is the backend that decides what those keys sign. Bitget's statements place this incident on the backend side and rule out private key compromise.

However the signer is structured, it has no independent view of whether a request is legitimate. It signs what the backend presents. Protecting the key material, even across an MPC setup, does not help when every party that signs takes its instructions from the same compromised backend. A valid signature can still authorize a harmful transaction.


Securing Wallet Operations with Blockaid’s Cosigner

However an exchange configures its custody and wallet signing authority, an independent cosigner with its own threat intelligence, tuned to the anomalies of a drain in progress, can stop funds from leaving. Cosigner validates every withdrawal before it is signed, on infrastructure the attacker does not control. For Bitget, as for any custody operation, that check would have sat between the compromised backend and every signature in this drain.

Cosigner: Real-time transaction screening and policy enforcement across custody infrastructure

Automated signing that trusts a single backend is a standing risk for every exchange and custodian, and it is the risk Cosigner is built to remove. Cosigner is an independent validation layer that sits between transaction creation and execution. Every transaction is simulated before signing, so the security team sees the actual onchain outcome, which assets move, how much, and to whom. Cosigner then validates that outcome against the organization's policies and patterns, including transaction size, destination address, velocity, and first-time recipients. Blockaid's machine learning models and threat intelligence score each transaction for risk. Cosigner co-signs clean transactions, rejects the rest, and alerts the security team in real time.

Cosigner runs on Blockaid infrastructure, separate from the customer's, and supports major MPC and multisig providers including Fireblocks, BitGo, Safe, and more.

In this instance, Cosigner would have simulated and validated every withdrawal Bitget's backend pushed through before it was signed. The transfers in this attack stood out on exactly the patterns Cosigner checks, tens of millions of dollars per transaction, sent to newly created addresses with no history, from several hot wallets inside the same short window. That gives the exchange a detection and alerting layer outside the compromised backend. Spoofing the backend's data does not change what Cosigner sees, because it evaluates the raw transaction the wallet is about to sign.

With a required key share in the MPC quorum or a required signature on a multisig, a transaction cannot complete without Cosigner's approval, and these transfers would have been declined at the first attempt. With a lighter integration, Cosigner's alert on the first malicious transfer triggers a halt of the signing flow, which caps the loss at that transaction. 


Ongoing Visibility and Protection Over Deployed Contracts with Blockaid’s Onchain Monitoring

The other half of the defense is watching the chain itself. However clean every signature looks, the chain records what actually happened, and Onchain Monitoring flags malicious behavior the moment it lands, including sudden large transfers to unauthorized external wallets.

Blockaid's Onchain Monitoring continuously tracks the wallets, contracts, and infrastructure an organization depends on, including treasury, hot, and multisig wallets. Machine-learning-driven detection flags malicious transactions, suspicious token transfers, and anomalous outflows as they land onchain. Each alert can trigger an automated response, such as alerting the security operations team in Slack, denying a Cosigner signature, pausing contracts, or notifying third-party wallets.

The first large transfer left Bitget's hot wallet at 18:58 UTC, roughly $35M in USDT, sent to an address funded with gas 27 minutes earlier. A monitor on hot wallet outflows, with rules on transfer size, velocity, and first-time recipients, would have flagged that transfer as it landed. From there, the outcome depends on response speed. An automated response that denies the Cosigner signature or pauses the signing flow stops every later transfer and keeps roughly $317M, about 90% of the loss, in Bitget's wallets. A human-led freeze within 15 minutes would still have stopped the ~$185M wave at 19:16 and everything after it.

Together, Cosigner and Onchain Monitoring give an institution the means to stop a drain in progress and to limit the contagion from incidents elsewhere in the ecosystem.


Blockaid’s Ecosystem Role: Preventing Contagion Across the Rest of the Onchain Economy

Outside of Bitget’s own security perimeter, Blockaid provides solutions for other participants to effectively thwart the attacker, secure their own operations  and protect the greater onchain economy.

Partnering with the Ecosystem

SInce yesterday, Blockaid has been working not just with Bitget but also with asset managers, protocols, etc across multiple chains, to provide them with advise and guidance around this. We take huge pride in being true partners, and this is what we believe the ecosystem needs the most in times of exploit.

The Blockaid Ecosystem Incidents Feed Surfaces Risk Events

The Ecosystem Incidents Feed in the Blockaid platform gives security teams a live view of incidents across the industry, including exploits, front-end attacks, compromised keys, and signing infrastructure breaches like this one. Teams filter it to the chains and protocols they care about, and it sits alongside their own monitoring, so intelligence on what is happening elsewhere and protection of their own assets live in one place. Monitoring customers were alerted to the Bitget exploit through the Ecosystem Incidents Feed, equipping teams with the intel needed to investigate and form appropriate responses as the attack was playing out.

Learn about the Ecosystem Incidents Feed →

Risk Exposure Screens For Illicit Funds in Real-Time 

Once Blockaid flags an address as belonging to an exploiter, that intelligence flows into Risk Exposure in real time. Risk Exposure screens counterparties and monitors DeFi pools for toxic flow, meaning funds tied to exploits moving through them, so regulated institutions, liquidity providers, and exchanges can see when they are transacting with the Bitget attacker, directly or a few hops removed. A liquidity provider can withdraw from a pool the attacker is using as exit liquidity, and a compliance team has a record that it acted on the alert.

Learn about the Blockaid’s Risk Exposure →


Looking Ahead

The Bitget drain was a custody authorization compromise. The exchange's own signing process was made to approve transfers the exchange never intended, and every control that trusted the backend approved them too. A valid signature only proves the keys were used, and any signing flow that takes instructions from a single system inherits that system's compromises.

Blockaid will keep tracing the funds and sharing attacker addresses with the ecosystem as they move, and will update this post when Bitget publishes its full technical report. The incident remains live on the ecosystem feed, and Risk Exposure is carrying the attacker's addresses to counterparties across the industry.

Every operator onchain needs detection that catches an attack in progress and a response that acts on the first bad transaction. For exchanges and custodians, that means onchain monitoring on hot wallets and an independent cosigner on every withdrawal signature. Blockaid provides both today, alongside the ecosystem feed and Risk Exposure that carry each incident to the rest of the ecosystem. To see how they would fit your stack, talk to our team.

Request a Demo →


About Blockaid

Blockaid is the onchain security platform trusted by the largest companies operating in Web3. Built by veterans of elite intelligence and cybersecurity units, Blockaid provides end-to-end protection for financial institutions, protocols, and end users, combining direct wallet and dApp integrations with real-time monitoring, detection, and response across smart contracts, infrastructure, and externally owned accounts. Since 2025, Blockaid scanned over 6.3 billion transactions and blocked 585 million attacks. Blockaid is the security infrastructure behind Coinbase, MetaMask, Uniswap, Safe, and dozens of the most widely used platforms in the industry.

Learn more at blockaid.io, and follow us on Twitter and LinkedIn.


Blockaid is securing the biggest companies operating onchain

Get in touch to learn how Blockaid helps teams secure their infrastructure, operations, and users.