An address suspected of involvement in the Bitget hack transferred approximately $1.23 million in funds after withdrawing them from Binance. On Sept. 26, wallet 0x4885 withdrew 257.6 ETH, valued at roughly $692,000, and 545,000 USDT from the exchange, according to on-chain monitoring.
The address swapped all 545,000 USDT for 200.2 ETH. The accumulated 457.9 ETH—totaling about $1.23 million—was then transferred in full to a wallet associated with the Bitget attacker.
The Bitget security breach was detected Sept. 24 at 18:31 UTC, resulting in unauthorized transfers initially estimated at $351.6 million but later revised upward to $387.5 million. On-chain analysis revealed five separate withdrawals from Binance's hot wallets on Sept. 25, including approximately 88.35 ETH, 89.36 ETH, 79.93 ETH, and roughly $545,000 in USDT.
Investigators are tracing the stolen funds across Ethereum, BNB Chain and TRON. The attack affected multiple assets—ETH, XRP, BNB, AVAX, USDT and USDC—with XRP recording the largest single-chain loss.
Unlike typical exchange hacks, the attacker did not steal private keys or breach cold storage. Instead, they compromised Bitget's backend system, allowing them to spoof transaction data and trick the system into authorizing transfers that appeared legitimate internally but routed funds to the attacker's addresses.
Bitget paused withdrawals shortly after detecting the breach and pledged to cover all customer losses through its User Protection Fund, which holds over $464 million. Both Bitget and Binance confirmed collaboration on tracing the stolen funds.
Mandiant, SlowMist and blockchain analysis firms including Bitquery are assisting in the investigation. IP address patterns have led some analysts to speculate about possible North Korean-linked actors, aligning with the sophisticated multi-chain laundering techniques documented in attacks attributed to groups like Lazarus Group. Authorities have not confirmed this attribution.

