Bitget hack: 68,465 ETH sit on eight attacker wallets, untouched

PublicAML · On-chain investigation · 25 September 2026

On 24 September 2026 Bitget lost $351.6 million from its hot and warm wallets. Lookonchain has already broken the total down by asset — the largest slice is 102.93 million XRP — and reported that the attacker swapped most of the EVM proceeds into roughly 68,000 ETH. This page maps that ETH on Ethereum address by address: three Bitget source wallets, one swap wallet, one hub, eight bridge intakes and eight holding wallets. As of 25 September the holding wallets have not sent a single transaction, and about $318,000 in USDT and USDC that Tether and Circle can still freeze sits on one of the attacker’s wallets.

68,465 ETH

on the attacker’s Ethereum wallets, 25 Sep (~$183M)

8

holding wallets — six of exactly 10,000 ETH

3

Bitget wallets it came from on Ethereum (Bitget 5, 6, 35)

$318K

USDT and USDC still freezable on one attacker wallet

What is already known

Bitget says unauthorized transfers began at 18:31 UTC on 24 September and that $351.6 million left its hot and warm wallets; it froze withdrawals for all users and has not named a final attack vector. Early on-chain estimates of $174–192 million covered only the EVM chains. The gap was closed by Lookonchain’s breakdown: 102.93 million XRP (about $157 million) is the largest single asset, ahead of ETH, stablecoins, XAUT, BNB, AVAX and TRX. The XRP route has been followed by bitcoin.com and others. None of that is ours, and this page does not repeat it.

Three Bitget wallets on Ethereum

The attacker’s first wallet on Ethereum is 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee. It received a 0.84 ETH test from Bitget 6 (0x1AB4973a48dc892Cd9971ECE8e01DcC7688f8F23) at 18:31, then 34,751,168 USDT, 12,852,046 USDC and 9,234 ETH from the same wallet, and 3,000.32 XAUT from Bitget 5, 0x5bdf85216ec1e38D6458C870992A69e38e03F7Ef.

The larger share of the ETH came from a third wallet, Bitget 35 (0xffa8DB7B38579e6A2D14f9B347a9acE4d044cD54, labelled so on Etherscan and topped up by Bitget 6 in the normal course of business): 15,361.83 ETH in three transfers at 19:03, 19:16 and 20:09. Taken together, the attacker pulled 24,596.6 ETH straight out of Bitget on Ethereum.

When (UTC, 2026)FromToAmountTx
24 Sep 18:580x1AB497…8f8F230x770b10…8463Ee34,751,168 USDT
out of Bitget 6
0xa3ae35…599ce5
24 Sep 19:010x1AB497…8f8F230x770b10…8463Ee12,852,046 USDC
out of Bitget 6
0x40903f…7ad7ae
24 Sep 19:010x1AB497…8f8F230x770b10…8463Ee7,130.86 ETH
out of Bitget 6
0x67a7ac…48930c
24 Sep 19:160xffa8DB…44cD540x770b10…8463Ee13,965.93 ETH
out of Bitget 35
0x846980…f60bfa
24 Sep 19:070x770b10…8463Ee0x7c9627…573E1C34,751,168 USDT
to the swap wallet
0xeee3f6…7c5867
24 Sep 19:300x7c9627…573E1C0xA6dD3F…65554522,320 ETH
stablecoins sold for ETH
0xbf4235…bdd36a
24 Sep 20:130x770b10…8463Ee0xD2C2f0…d9F89910,000 ETH
to a holding wallet
0xf5ae8d…efedd3
24 Sep 20:190x770b10…8463Ee0x600cfe…5784b210,000 ETH
to a holding wallet
0x32df60…1d13d5
24 Sep 21:410x770b10…8463Ee0xDc2901…91dC634,590 ETH
to a holding wallet
0xcdd19d…e48a76
24 Sep 21:570xA6dD3F…6555450x9FA39d…eA4FA010,000 ETH
to a holding wallet
0x872dd5…a4ede1
24 Sep 21:580xA6dD3F…6555450xA6BFd7…2dB27210,000 ETH
to a holding wallet
0xd955a1…8ec288
24 Sep 22:000xA6dD3F…6555450xFd5EBe…3f9e549,000 + 1,000 ETH
to a holding wallet
0x0399da…dad695
24 Sep 22:350xA6dD3F…6555450xeD5a39…bE1A518,660 + 1,340 ETH
to a holding wallet
0xc26058…a8d33b
24 Sep 23:370xA6dD3F…6555450x52f08F…25d2843,698.10 ETH
to a holding wallet
0xca6f73…681e65

Stablecoins to ETH in half an hour

USDT and USDC can be frozen by their issuers, ETH cannot. Between 19:07 and 19:46 the attacker moved the stablecoins and the gold token to a wallet running an EIP-7702 delegation, 0x7c96279Ec1e888Aa56b9B836e0dB26ca48573E1C, and sold them through UniswapX Dutch orders and Uniswap pools for 22,612.7 ETH. That ETH went to a hub, 0xA6dD3F218B65E32Ccc37BE30f74884133c655545, in two transfers (22,320 and 292 ETH).

The same hub then collected about 21,000 ETH more from wallets that received it through bridges — Stargate, Across and deBridge — and from swaps on Ethereum. The attacker used the same addresses on Arbitrum, BNB Chain, Avalanche, Base and Optimism; on 25 September they hold almost nothing there. Everything that was converted has been brought home to Ethereum.

Where it sits now

From the first wallet and from the hub the ETH was cut into round lots and parked: six wallets of exactly 10,000 ETH, one of 4,596.47 and one of 3,698.10. Together with 170 ETH left on a bridge intake that is 68,465 ETH, about $183 million at the 25 September price. Not one of the holding wallets has sent a transaction since it was filled.

The eight holding wallets, as of 25 September: 0x9FA39d62095302431d7d4167a7E80F8Ec6eA4FA0, 0xA6BFd7FcaF4711dA1f61D5E91d03A2c7C72dB272, 0xFd5EBe912e2061992437767e24e5BCb52a3f9e54, 0xeD5a394a7558929112848B7e97B569de6bbE1A51, 0xD2C2f029eFF5caCc686F24377CfdDcfc82d9F899, 0x600cfeDc6Bd65Fa79B604dC44964f419e45784b2 (10,000 ETH each), 0xDc2901f741B4003e32B8B752e97b8c4C1891dC63 (4,596.47 ETH) and 0x52f08Feb1B0Da609A5442514E2Bb43C99D25d284 (3,698.10 ETH).

One intake wallet, 0xe07Bd590E1198666230932BAd5db3DbBE21e7d57, still holds 218,023 USDT and 99,990 USDC. Those two can still be frozen by Tether and Circle.

The attacker is being targeted in turn: look-alike addresses sharing the first and last characters of the attacker’s wallets (0x7C93…3e1C for 0x7c96…3E1C, 0xA6DD…, 0xDc29…) have been sending zero-value transfers and fake “ETH” and “USDT” tokens to them. That is address poisoning, aimed at whoever copies an address from the history next.

What this page does not say

It names nobody. Bitget has pointed to a North Korea-linked group but called that unconfirmed; this page adds nothing to it. An on-chain investigator has linked the XRP routing to July’s AFX exploit. We checked the Ethereum side for that link — two hops out from the AFX exploiter’s wallet 0x627654B2782BFc57580ecd11d40869B350b6EBaC — and found no shared address, which neither confirms nor rules it out.

All 20 attacker addresses on Ethereum are labelled in the PublicAML risk graph and listed on our incident page. The holding wallets are watched: the page will be updated when any of them moves.

Sources: Ethereum chain data (Blockscout) and public RPC for Arbitrum, BNB Chain, Avalanche, Base and Optimism, read on 25 September 2026; totals by asset and the XRP route as published by Lookonchain, bitcoin.com and Cryptotimes; Bitget’s statements as reported on 24–25 September. This is an information resource about transactions between addresses, not financial or legal advice, and it names no individual as responsible for anything.