Getting your Trinity Audio player ready...

TL;DR: A major Bitget exploit exposes weaknesses in crypto security, with $388 million in assets stolen and much of the haul moved through THORChain. As Bitget works to recover the funds, a separate dispute is unfolding over claims that Coinbase concealed more than $1 billion in hacks.

Key Takeaways:

The Bitget digital asset exchange is recovering from the sector’s latest nine-figure exploit, while Coinbase (NASDAQ: COIN) is denying public claims that it suffered similar hacks without disclosing their impact.

On September 24, Bitget announced that its security systems had “identified unauthorized transfers involving a limited number of hot wallets.” Emergency measures were activated, but not before “approximately $351.6 million in assets were affected.”

The company temporarily suspended withdrawals but stressed that user funds “remain protected” and that the enormity of the breach nonetheless “falls within the coverage of Bitget’s User Protection Fund,” which held $464 million at the time.

The company said it wouldn’t “speculate on the attack vector,” but online sleuths quickly flagged North Korea’s infamous Lazarus Group of state-sponsored hackers as the culprit. In a livestream later that day, Bitget CEO Gracy Chen agreed, saying “based on IP behavioral patterns and on-chain signatures, this attack is consistent with techniques used by DPRK-linked hacker groups.” 

In an interview with The Block a few days later, Chen said the hack was still being blamed on “the same group of people that we suspect.” Chen also revealed that private keys and cold wallets weren’t compromised. Instead, the attackers exploited a zero-day vulnerability in “a third-party security product to obtain high level internal credentials.”

The attackers then inserted fraudulent withdrawal commands into backend systems governing wallets. Once the funds were withdrawn, the attackers deleted the fraudulent commands, giving them more time to make good their escape while Bitget’s engineers struggled to figure out what happened.

Slowmist analysts enlisted by Bitget to investigate the attack released a report indicating the attackers began exploiting this zero-day on August 31. The attackers used “a highly customized withdrawal tool … tailored to the wallet system’s withdrawal logic. It forged risk-control parameters in its code, constructed withdrawal requests, and invoked the withdrawal process.” The report claims the attackers might have gotten away with even more funds had two fabricated BTC withdrawal orders not returned errors.

After patching the vulnerability that led to the exploit, Bitget began a phased resumption of withdrawals on September 28. The exchange said it hopes to have resumed withdrawals and P2P transactions of all tokens by Friday (October 2).

Following the exploit, Bitget launched a recovery bounty program covering “eligible voluntary actions” that result in funds being frozen and “future actions that directly contribute to the freezing or recovery of funds.” In each case, 5% of the funds frozen or recovered will be available as a bounty.

The bounty doesn’t apply if entities or individuals who freeze/recover are ordered to do so by courts or law enforcement agencies. Bitget will also use the LazarusBounty initiative set up by Bybit following its 2025 hack.

More like LOKIChain

The hackers made off with a variety of tokens, including Ethereum’s native token ETH, the USDT and USDC stablecoins, and the Binance Smart Chain’s BNB, but the “largest single chain loss” involved Ripple Labs’ XRP (roughly $83 million worth). Chen said Bitget had “contacted foundations across all affected chains,” a few of which had “frozen the hacker’s wallet addresses.”

USDC-issuer Circle (NASDAQ: CRCL) and USDT-issuer Tether collectively managed to freeze roughly $318,000 worth of their tokens. But the overwhelming bulk of the stolen tokens—the total value of which was soon raised to $388 million—were transferred and converted, some via the THORChain cross-chain bridging platform.

Chen publicly pleaded with THORChain “to refuse service to these addresses.” Addressing the mantra of so-called 
decentralized finance (DeFi) platforms, Chen said “decentralization is a design principle, not a shield for facilitating known stolen funds. The industry is watching.”

The next day, THORChain’s developers responded to Chen’s plea by saying they were “devastated to hear about the recent exploit,” but their platform is “decentralized and permissionless,” so their hands were tied.

And yet, THORChain flipped its ‘halt’ switch in May when it was the victim of an exploit that stole nearly $11 million. When this was pointed out following the platform’s Bitget shrug, THORChain argued that halting its network “is an emergency security mechanism designed to protect the protocol. A halt is not a selective freeze of specific funds or an individual swap … THORChain is permissionless and doesn’t censor by design.”

THORChain has become a popular getaway car for crypto’s bad actors. In February 2025, the Bybit exchange was hacked for $1.5 billion by Lazarus, and the bulk of this sum followed a similar chain-hopping pattern via THORChain.

In a separate hack this January, THORChain had the gall to use the exploit to promote the speed and sturdiness of its platform, tweeting that “when infrastructure works, whales keep coming back.”

Chen told The Block that she was “a little bit frustrated” by THORChain’s initial dismissal of her plea, but she was simply too busy at the time to respond. However, Chen added that “this is like a repeated pattern that we see, that hackers use THORChain to launder the stolen assets … so while respecting the permissionless design fully, we also want to talk to them … to understand what’s technically and governance-wise possible so that we can find something workable together.”

Back to the top ↑

‘Coinbase was hacked’ claims set off social media fight

On September 27, Jordan ‘Cobie’ Fish responded to an X user complaining that Coinbase “stole $1,200,000 from me” and had failed to respond to the user’s requests for help.

Cobie, the developer behind crypto crowdfunding platform Echo that Coinbase acquired last year and who now runs the exchange’s layer-2 network Base, tweeted that he’d “looked into the account” and concluded that “this situation is being used to promote a shitcoin, so looks basically to be entirely fake/scam report/engagement farm.”

But Cobie’s tweet immediately received a reply from Ari Paul, co-founder of the crypto/tradfi institutional investment firm BlockTower Capital (now part of Arca), who dropped this bombshell:

“Coinbase ‘lost’ $25m of my firm’s a couple years ago. Turned out they were actually covering up massive and repeated hacks. Still wouldn’t return our money. We traced this to at least a dozen other affected firms and over $1b covered up. That’s all I can say for now as multiple legal processes still ongoing.”

Coinbase Support’s X account quickly replied that it had sent Paul a DM “so we can look into this right now with you.” The next day, Coinbase Support tweeted that it couldn’t comment on specific clients but wanted to “share some general facts to clear up any incorrect speculation.

Coinbase is not hiding a series of hacks and we certainly didn’t lose $1B.”

A few hours later, Paul tweeted a much lengthier message, saying: “I can’t share proof yet since multiple legal processes still unfolding and Coinbase already tried to sue me into silence (unsuccessfully, but I need to be smart about how I fight the 800 pound legal bully).”

Paul insisted that “every word I’ve written is true, I have no ulterior motive, nor position long nor short, Coinbase or related equity. I’m still heavily long crypto, so if anything, I’d be incentivized to help Coinbase cover this up as many industry leading firms have ‘for the good of the industry’, but I won’t do that.”

Paul went on to allude to crypto companies “funneling billions in customer assets to Lazarus group and lying about it to investors, customers, regulators, and the secret service.” Paul called Coinbase’s claims that it was never hacked “radically false” and accused the exchange of “knowingly ‘misleading’ customers and investors about this, deliberately, over time.”

Addressing Coinbase’s lawyers, Paul said “it would be in the interest of the industry and the world…but not your executives for us to go through discovery and air all this out. I encourage you to assert this as libel so we can go through discovery and see if a single word of my writing is untruthful.”

Other X users asked Paul if his claims had anything to do with 2024 reports of BlockTower Capital’s main hedge fund having been ‘compromised and partially drained by fraudsters.’

Paul responded by noting that his team “never spoke to journalists in real-time. When [that article] came out, we weren’t sure whether we or Coinbase got hacked, as investigation hadn’t happened yet.” Paul added that the reporter “just assumed we got hacked. No reason to think that other than Coinbase saying it.”

Coinbase has yet to respond to Paul’s lengthy missive, at least, not publicly. But former Coinbase exec Justin Mart weighed in with his own theories, suggesting that BlockTower’s Coinbase account credentials might have been illicitly obtained and the account drained, possibly by the Lazarus Group. “Ari freaks out, blames cb, etc etc.”

Mart added that “Ari knows he will lose in court. But until then, he can lash out with these incredibly sensational claims and stir up some measure of public pressure to try to gain leverage in the process.”

Paul responded that BlackTower “ultimately traced the hack to a specific Coinbase codebase, the same attacker, (likely Lazarus group, but we’re not 100% sure) repeatedly compromised Coinbase over many months, targeting many different user accounts.” Paul added that “if Coinbase agrees not to harass or sue for me for it, I will release the full dossier with full detailed proof.”

Mart replied that “quite significant allegations … should require significant proof.” Mart urged Paul to take the matter to court, but said he remained “heavily skeptical” of Paul’s claims. “You can even keep this tweet as a receipt if I’m proven wrong, but I’m definitely not holding my breath. Good luck.”

Back to the top ↑

FAQs:

How did the Bitget attackers gain access?

According to Bitget CEO Gracy Chen, the attackers exploited a zero-day vulnerability in a third-party security product to obtain high-level internal credentials. They then inserted fraudulent withdrawal commands into backend systems governing Bitget’s wallets.

Who did Bitget suspect was behind the attack?

Chen said the attack was consistent with techniques used by DPRK-linked hacker groups. Online investigators had also pointed to North Korea’s Lazarus Group as the suspected culprit.

What happened to the stolen Bitget assets?

The attackers stole several tokens, including ETH, USDT, USDC, BNB and XRP. XRP accounted for roughly $83 million of the losses on a single chain. Much of the stolen crypto was subsequently transferred and converted, including through THORChain.

Why did Bitget criticize THORChain?

Bitget CEO Gracy Chen asked THORChain to refuse service to addresses associated with the stolen funds. THORChain responded that its platform is decentralized and permissionless and therefore could not selectively freeze specific funds or individual swaps.

What are the allegations against Coinbase?

Ari Paul, co-founder of BlockTower Capital, alleged that Coinbase had covered up repeated hacks involving more than $1 billion in losses. He said his firm had lost $25 million through Coinbase and that the incident was connected to other affected firms.

Back to the top ↑

Watch | WFIS 2025: The expert verdict on security vs. UX

Advertisement
Advertisement