Main/News blog/
How Bitget was actually breached: forged transfers and 7,111 ETH in six minutes

How Bitget was actually breached: forged transfers and 7,111 ETH in six minutes

How Bitget was actually breached: forged transfers and 7,111 ETH in six minutes
Max
26/09/2026
Authors: Max
#Cases
While you're thinking — others are already earning
with ArbitrageScanner!
Try ArbitrageScanner, find arbitrage opportunities and make profit. Buy a subscription now and get +30% bonus days for free!

How Bitget was actually breached: forged transfers and 7,111 ETH in six minutes

The first reports of a hack are always the same. So much was stolen, we are investigating, details later, and only a day on does the mechanism become clear and you can see which door they walked through. At Bitget it turned out to be an unexpected one.

The private keys were not stolen. The exchange's management said so directly, and that changes the whole picture: what was broken was not the cryptography but an ordinary corporate system. From what we see, that is exactly how money leaves venues today, not through guessing keys.

What forging transfer data means

Simplified, an exchange is built in two layers. There is an internal system that decides who gets sent what, and there is a signing module that executes that command and pushes the transaction into the network.

The keys sit in the second layer and are well protected. The first layer, though, is ordinary software that can be broken the same ways as any corporate system: through a vulnerability, through a contractor, through an employee.

After that the attacker does not need the keys at all. It is enough to slip the signing module a command with a substituted recipient address, and the exchange itself, with its own hands, will send the money wherever it is asked. The signature is entirely legitimate.

The six minutes in which it was all over

The speed of the laundering is more impressive than the sum. One of the freshly created addresses received USDT0 worth 19.67 million dollars and swapped it for 7,111 ETH in six minutes.

The logic is clear. A stablecoin can be frozen at the issuer's request, ether cannot, so the attacker's first task is to get out of freezable assets into unfreezable ones as fast as possible.

Hence the race. The exchange's security team tries to make it in time with a freeze request, while the attacker tries to make it in time with the swap and dissolve. Six minutes show who had prepared in advance.

Stage

What happened

Entry point

a breached backend system

What was forged

the transfer records

Keys

compromise ruled out

Laundering

$19.67M of USDT0 into 7,111 ETH in 6 minutes

Cold storage

untouched

Why the cold wallets survived

The separation scheme worked exactly as intended. A cold wallet is physically not connected to the system that makes transfer decisions, so forging a command for it is impossible.

The price of that protection is speed. Withdrawing from cold storage requires manual steps and time, which is why exchanges keep the bulk of funds there and a working balance for current operations in the hot layer.

We reckon it is the proportion between these layers that is the main figure worth looking at when choosing a venue. The ratio is rarely published, but the size of a loss relative to turnover says plenty after the fact.

What follows from this for us

First. A smart contract audit and a reputation in crypto security say nothing about how well protected a venue's corporate network is. These are different disciplines, and it is the second that gets broken more often.

Second. The speed of your reaction barely matters: by the time you are reading the news the money has already been swapped and sprayed across addresses.

Third and practical. The only protection that works is to cap the amount on each venue in advance. In our view a balance on an exchange should equal the volume that actually circulates through your pairs in a week, not your entire working capital.

Our tools

When a venue drops out, the routes have to be reassembled on the move. Our arbitrage screener keeps dozens of venues in one window, refreshes quotes every second and shows each gap together with the volume actually behind it. The spread calculator helps you check what survives fees, network costs and slippage at your size. The bot is fully manual. It never connects to your exchange API keys.

To test the tools on a live market, ArbitrageScanner offers one day of free access to the whole ecosystem.

FAQ (Frequently Asked Questions)

1. If the keys were not stolen, how did the money leave?

Through a forged transfer command. The attacker got access to the internal system that forms withdrawal instructions and substituted the recipient address inside them. After that the signature went through as normal.

2. Why was the stablecoin swapped for ether so fast?

An issuer can freeze a stablecoin on request, ether it cannot. So the attacker's first task is to get out of the freezable asset, and six minutes show the scenario had been prepared in advance.

3. Why did the cold wallets survive?

They are not connected to the system that makes transfer decisions. Forging a command for them is physically impossible, though withdrawing from there also requires manual steps and time.

4. Could a user have prevented this?

Prevented it no, limited the damage yes. Only one thing works: keeping on a venue a sum whose loss you would survive, and not concentrating all your capital in one place.

5. What does a hack like this say about exchange security?

That its cryptographic part was in order while its corporate network was not. Different teams protect these things, and they have to be judged separately from each other.

Conclusion

The most unpleasant thing about this story is how ordinary it is. Not a brilliant break of cryptography but an intrusion into corporate software and a substituted transfer instruction, a scenario familiar to any bank.

The crypto industry spent years investing in key protection and multisignature, and it gets broken through the same door ordinary companies get broken through. For a practitioner the conclusion is single: judge not only how reliably a venue stores coins but also the size of the sum you keep there.

IMPORTANT! We are software developers. We do not give recommendations or promises of earnings and we do not advise you to invest your money anywhere. Our software is fully manual, all your money stays under your own control. We show examples of how our clients have earned on arbitrage in the past, but we do not advise repeating those actions one to one. Your earnings depend solely on your own actions and on market factors.

Want to learn more about crypto arbitrage?

Get a subscription and access the best tool on the market for arbitrage on Spot, Futures, CEX, and DEX exchanges.

Want to learn more about crypto arbitrage?
Main/News blog/
How Bitget was actually breached: forged transfers and 7,111 ETH in six minutes

Subscribe to us on social networks:

Official YouTube channel of ArbitrageScanner.io

Subscribe to not miss useful content
Subscribe