Bitget Exchange Loses $387 Million After Attacker Bypasses Transaction Approval Controls
An adversary transferred $387.5 million from Bitget’s online wallets by subverting the platform’s approval process; offline wallets remained untouched. The breach underscores the need for robust access controls and continuous monitoring of privileged transactions for audit readiness.
ADTP Breach Watch· October 1, 2026· DataBreachToday
Bitget reported that an attacker moved roughly $387.5 million from its online cryptocurrency wallets by altering transaction information and tricking the internal approval system. Private keys were not stolen and the exchange’s cold‑storage wallets were unaffected. Withdrawals were halted on September 24 after the illicit transfers were detected.
Why it matters for trust and compliance
The incident demonstrates a failure of access‑control and transaction‑approval safeguards that continuous‑control‑assurance programs are designed to enforce and evidence, emphasizing the importance of immutable logging and real‑time monitoring for audit readiness.
Shows the necessity of continuous monitoring of privileged transaction approvals to detect anomalies early.
Provides concrete evidence for audit readiness around segregation of duties and multi‑factor approval processes.