← Back to blog

The Bitget hack on chain: three hours of swaps and bridging, 68,000 ETH parked in 8 wallets

As of 12:15 on September 25, about 98% of the roughly $193 million in stolen funds visible on chain was still sitting in wallets on the attacker's side, not at any exchange. Using public on-chain data, we walk through the swaps, bridging, consolidation and splitting in order.

Published Incident reviewFund tracing 阅读中文原文

At 02:31 in the early hours of September 25, 0.84 ETH moved from a Bitget hot wallet to a fresh address. It was a test. Twenty-seven minutes later, 34.75 million USDT followed it.

Bitget has confirmed that about $351.6 million was stolen from its hot wallets. Using public on-chain data, we traced the part of the money that can be seen, from the start. Here is the conclusion up front:

As of 12:15 today (September 25), about $193 million of the stolen funds is visible on chain, and about 98% of it is still sitting in wallets on the attacker’s side. None of it has gone into an exchange.

The attacker’s method is also clear: stablecoins were swapped into ETH within minutes of arriving, shutting off any chance for the issuers to freeze them; money on other chains was bridged back to Ethereum, consolidated into one address, split into lots of 10,000 ETH each, and finally parked in 8 wallets.

What follows goes in chronological order. All times are Beijing time (UTC+8).

$350 million or $190 million?

First, why the two numbers don’t match.

$351.6 million is Bitget’s internal tally of the loss, covering its hot wallets and part of its warm wallets. The figure of roughly $190 million is what on-chain analysts counted from public addresses: Etherscan has already labeled the receiving address Bitget Exploiter 1, and every transfer into it can be looked up on chain by anyone.

We queried public data on Dune for six chains — Ethereum, Arbitrum, Optimism, Base, BNB Chain and Avalanche — and arrived at $192.6 million, broadly in line with the “nearly $192 million” cited by CryptoSlate. Where the remaining $160 million or so went — possibly to chains we didn’t check, such as Bitcoin, Solana or TRON, or out of warm wallets without public labels — this article does not speculate.

Step one: how the money left

On the sending side were 4 addresses that Dune labels as Bitget. Across 6 chains they made 16 transfers, all to the same attacker address, 0x770b…63Ee:

  • At 02:31, 0.84 ETH was sent as a test — the same minute Bitget says it “detected an anomaly at 02:31”;
  • At 02:58, 34.75 million USDT;
  • Around 03:01, within half a minute, 6 transfers went out simultaneously on four chains — Ethereum, Arbitrum, Optimism and Base — totaling about $84 million in USDT0, USDC, the gold token XAUt, and ETH;
  • At 03:16, 3 more transfers totaling about $56 million, one of them 13,966 ETH;
  • At 04:09, another 3,275 ETH, and at 04:55, 8.2 million USDC on Avalanche;
  • The last one was 223 ETH at 05:23.

That last transfer is worth pointing out. Public reports put the outflows as ending at 04:55, but the chain shows that Bitget’s hot wallets were still sending money to the attacker’s address as late as 05:23 — just 7 minutes before Bitget’s official announcement at 05:30.

Figure 2: timeline

If you look this address up on Etherscan yourself, the records are a mess: lots of tokens also called “USDT” or “ETH” that use look-alike characters, and many unfamiliar addresses whose first and last few characters exactly match addresses the attacker often uses. This is address poisoning — people deliberately spray fake records onto high-value addresses, hoping someone copies the wrong address. Of the 149 transfer records on this address, more than a hundred are fakes like these. You have to check each one against the token’s contract address.

Step two: every stablecoin gone within minutes

The first thing the attacker did with the money was get rid of the stablecoins.

The reason is simple: USDT and USDC are backed by issuing companies, and an issuer can freeze the coins held by a given address. ETH has no issuer, so nobody can freeze it. The longer stolen stablecoins sit around, the more likely they are to be frozen.

So the attacker moved fast:

  • After the 34.75 million USDT landed in intermediary address 0x7c96…, it was completely sold in 7 trades in under 10 minutes;
  • 12.85 million USDC was sold off just over two minutes after it arrived, and 3,000 XAUt was sold within seven minutes;
  • On Arbitrum, the 19.67 million USDT0 was handled by another intermediary address, 0xe410…; from 03:36 to 03:42 it was swapped into 7,111 ETH in 6 minutes.

The sales went through UniswapX and 1inch Fusion. Both work a bit like placing an order: the seller states “I’m selling this much and want at least this much back,” and professional market makers fill the order, so even large orders can be executed quickly.

Speed had a price. On Arbitrum, the 7,111 ETH cost about $2,766 each on average, while the market price at the time was around $2,695. The attacker overpaid by 2.6% on average — roughly $500,000. Being willing to pay extra to finish swapping before anything could be frozen says a lot about the attacker’s priorities.

There is another detail on Optimism: the attacker first swapped ETH into USDC, moved it to Ethereum through Circle’s official cross-chain channel, and swapped it back into ETH within a minute or two of arrival. Each time, stablecoins stayed in its hands for only a minute or two.

Step three: bridge back to Ethereum, consolidate, then split

Once everything was in ETH, the money began converging on Ethereum mainnet.

ETH on Arbitrum, Optimism and Base was bridged back to Ethereum through Across, Stargate and deBridge. A cross-chain bridge works like this: you hand it coins on chain A, and it pays you the equivalent coins on chain B. The USDC on Avalanche was first swapped into AVAX, then sent to several other intermediary addresses the attacker had opened, and bridged into ETH on Ethereum. These intermediary addresses use the same address on both chains, and Arkham has already labeled them Bitget Hacker. The BNB Chain portion was split up even more finely; more on that below.

From 03:30 onward, this ETH flowed one batch after another into a single consolidation address, 0xa6dd…5545. The first batch was the 22,320 ETH swapped on Ethereum. In total it received 43,698 ETH, and then, between 05:57 and 07:37, split it into lots of 10,000 ETH across 4 new wallets, putting the remainder into a 5th wallet, which received another 485 ETH at 11:45.

The 24,597 ETH that came directly from Bitget was neither swapped nor bridged. Between 04:13 and 05:41 the attacker address sent it straight into 3 other wallets, two of which received 10,000 ETH each.

Figure 1: flow of funds

Where the money is now

As of 12:15, the addresses below have only received funds and have sent nothing out. All of them are labeled Bitget Hacker on Arkham:

AddressChainBalance
0xd2c2f029eff5cacc686f24377cfddcfc82d9f899Ethereum10,000 ETH
0x600cfedc6bd65fa79b604dc44964f419e45784b2Ethereum10,000 ETH
0x9fa39d62095302431d7d4167a7e80f8ec6ea4fa0Ethereum10,000 ETH
0xa6bfd7fcaf4711da1f61d5e91d03a2c7c72db272Ethereum10,000 ETH
0xfd5ebe912e2061992437767e24e5bcb52a3f9e54Ethereum10,000 ETH
0xed5a394a7558929112848b7e97b569de6bbe1a51Ethereum10,000 ETH
0xdc2901f741b4003e32b8b752e97b8c4c1891dc63Ethereum4,596 ETH
0x52f08feb1b0da609a5442514e2bb43c99d25d284Ethereum3,698 ETH
0x150889fe4fa7a7699588f75c4189fa9e721acfd3BNB Chain5,897 BNB
0xe07bd590e1198666230932bad5db3dbbe21e7d57EthereumAbout 218,000 USDT, 100,000 USDC, 170 ETH

The 8 ETH wallets hold 68,294 ETH in total, worth about $183 million at current prices. Add the BNB and the remaining stablecoins and it comes to about $188 million — roughly 98% of the stolen amount visible on chain.

“Parked” doesn’t mean “safe.” The private keys to these wallets are in the attacker’s hands, and they can move at any time; ETH has no issuer that could freeze it. The only funds that can still be frozen are the roughly $320,000 in USDT and USDC in the last row.

Three things worth watching

First, which chain the $7.4 million went to. On the BNB Chain route, most of the 12,719 BNB went into intermediary address 0xe07bd…. On both BNB Chain and Ethereum, it split the money into dozens of small transfers and sent them to 5 very high-volume addresses, about $7.4 million in total. We checked the Arkham label for each one; none is an exchange:

  • About $4.61 million went into cross-chain bridges: $3.74 million into PancakeSwap’s cross-chain contract, $770,000 into Mayan, and $100,000 into Celer. This money has left the six chains we examined, and has to be followed from the other end of each bridge;
  • About $2.78 million went into the swap contract built into the MetaMask wallet and was exchanged for other tokens.

So far, none of the funds we traced has gone directly into an exchange.

Second, when the 8 wallets will move. Large amounts of stolen money usually end up in mixers or over-the-counter trades, or simply sit untouched until things quiet down. Splitting it into neat lots of 10,000 ETH looks like preparation for handling it in batches later. These addresses are already public, so exchanges and bridges can add them to their risk lists in advance.

Third, don’t mistake Bitget’s own transfers for theft. Around 04:40, Bitget-labeled addresses on several chains sent more than $50 million within a few minutes to the address 0xadfffc33…. Dune doesn’t label this address, so it is easy to misread as “a second attacker.” But it has been trading in both directions with Bitget’s hot wallets since August, receiving and paying out more than $100 million, and Arkham labels it as Bitget too. The more plausible explanation is that after discovering the theft, Bitget urgently moved the remaining assets in its hot wallets to its other wallets.

Closing thoughts

On-chain data is entirely public, but public doesn’t mean easy to see. In the three hours of this attack, the money changed tokens several times across 6 chains and dozens of addresses, with more than a hundred poisoned fake records mixed in. To say clearly “where the money is now,” you have to check every transfer for authenticity and stitch the swaps and bridging together in time order.

The figures in this article are as of 12:15 on September 25. If the funds move again, we will keep following them.


We focus on AI agents for on-chain fund tracing. We want them to take on the transfer-by-transfer searching, organizing and checking, while keeping every conclusion traceable back to the original records on chain.

If this direction interests you, or you’re dealing with a real problem like this in your work, feel free to get in touch.

Sources:

Got a clue, or an address?

Both products are in early access. We will run a real investigation with you and hand over the full results and evidence.