GoPlus Security analysis reveals Bitget's $387.5M hack exploited transaction-signing backend, not private keys, with attackers draining funds in a 2-hour window.
Security & Exploits ·
GoPlus Security's analysis of Bitget's $387.5 million security breach determined that the incident stemmed from a compromised transaction-signing trust chain rather than a private-key exposure. The attackers breached Bitget's wallet backend system, forged transaction data, and manipulated the exchange's authorized signing mechanism to generate valid signatures for unintended fund transfers.
The theft unfolded rapidly over approximately 2 hours and 25 minutes, with a single concentrated drain of roughly $185 million occurring within about one minute. GoPlus has since blacklisted addresses linked to the attackers and distributed this intelligence to ecosystem partners.
The attack bears structural similarities to the 2025 Bybit hack, according to GoPlus. However, Bitget has not yet released a comprehensive technical report, and the vector through which attackers initially gained access to the backend system remains unconfirmed.