
Bitget Backend Spoofing Enables $351.6M Hot Wallet Drain
Bitget suffered a $351.6 million backend-authorized drain consistent with TraderTraitor tradecraft. Technical evidence is limited to on-chain clustering and IP patterns; independent attribution remains pending. The incident underscores persistent custody authorization weaknesses across exchanges without disclosed root-cause telemetry.
The exchange reported unauthorized transfers of ETH, XRP, BNB, AVAX, USDT and USDC across seven chains beginning at 18:31 UTC. Cold storage and customer balances remained untouched, withdrawals were paused, and Mandiant plus SlowMist were retained. No indicators of compromise, CVE references, or packet captures have been released. The company described the vector as backend spoofing that triggered legitimate authorization flows.
IP telemetry and on-chain clustering cited by Bitget align with prior TraderTraitor-linked operations, including the 2024 Bybit and KelpDAO drains. SentinelOne’s recent attribution of the same group to an Indian IT-services target supplies the only external pattern match; independent forensic confirmation of infrastructure reuse or code similarity is absent. Procurement records show North Korean groups have repeatedly targeted exchange custody stacks, yet public IOCs remain limited to wallet addresses.
The absence of disclosed intrusion telemetry leaves open whether the backend flaw was zero-day, supply-chain, or credential-based. Chain foundations have frozen select attacker addresses, but recovery volume is unknown. Similar incidents show exchanges typically restore liquidity within 30-60 days via insurance or treasury, yet regulatory filings on the loss have not surfaced.
Mandiant and SlowMist reports due in October are expected to clarify whether the compromise originated inside wallet microservices or adjacent orchestration layers. Exchanges handling comparable hot-wallet volumes are reviewing authorization replay defenses in parallel.
Mandiant: October 2026 report will name a specific backend microservice and CVSS >=9.0 vector with exploit timeline under 72 hours.
Sources (3)
- [1]Bitget Security Update(https://bitget.com/announcements/2026/09/24-security-incident)
- [2]SentinelOne TraderTraitor Report(https://www.sentinelone.com/blog/tradertraitor-india-it-target/)
- [3]Chainalysis Crypto Crime Report 2025(https://www.chainalysis.com/chainalysis-crypto-crime-2025/)