More than $183 million in crypto assets was drained from Bitget-labeled wallets in an incident on Thursday night. According to analyst tracking and blockchain data, hundreds of millions of dollars moved from exchange wallets to several newly created addresses. The suspected cross-chain exploit executed massive asset transfers in less than an hour.
The abnormal activity hitting one of the world’s largest centralized trading platforms was picked up by on-chain monitors. Analyst teams from Bubblemaps and Arkham were the first to publicly flag the asset drain on the night of the incident.
First Signs from Hot Wallets
The initial traces of the suspected exploit began with movements in Bitget’s hot wallets. A newly created address controlled by the attacker, starting with ‘0xe410’, took $19.67 million in USDT0 - a cross-chain version of Tether’s stablecoin. Rather than merely moving the funds, the perpetrator immediately swapped the entire stablecoin balance into 7,111 ETH in just six minutes.
The ETH purchases were executed via decentralized exchange aggregators UniswapX and 1inch Fusion. Transaction data revealed the orders were filled at prices roughly 5% above the market rate. The decision to buy assets above fair value indicates the attacker prioritized the speed of fund movement over exchange rates.
Draining Network Tokens to Physical Gold Assets
The exploit extended well beyond USDT0 and ETH. Other Bitget wallets were observed transferring a variety of crypto assets to a single primary destination address: 0x469Ac1406dE92f82C0563477240a3627057425DC.
The attacker withdrew various types of coins from the exchange to consolidate them into that single holding address. The transferred assets included layer-1 network tokens such as AVAX and BNB, fiat stablecoins USDC and USDT, and XAUT tokens pegged directly to physical gold reserves. The attacker completed the withdrawal maneuvers across multiple blockchains in under an hour.
What We Don’t Know Yet
It is important to note that the transaction data, destination addresses, and estimated loss figures reflect the conclusions of independent analysts reviewing public on-chain records. As of publication time, Bitget management has not issued an official statement confirming an exploit on its wallet infrastructure.
Reported via Decrypt.
Read also: Returned 3,400 BTC but Kept 598 Stolen Liquid BTC - Immunefi CEO: It’s Pure Theft
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




