Bitget key compromise — $387.0M lost on Ethereum, XRP, Tron, Zcash
Bitget lost an estimated $387.0M on Ethereum, XRP, Tron, Zcash (hot wallet key compromised), according to the DeFiLlama hacks database. Users and integrators should review exposure and follow the project's official channels.
Vuln-watch · relayed from the DeFiLlama hacks database; see Source & attribution below
Summary
Bitget lost an estimated $387.0M on Ethereum, XRP, Tron, Zcash (hot wallet key compromised), according to the DeFiLlama hacks database. Users and integrators should review exposure and follow the project's official channels.
Incident
- Protocol: Bitget
- Date (UTC): 2026-09-24
- Estimated loss: $387.0M
- Chain(s): Ethereum, XRP, Tron, Zcash
- Technique: Hot Wallet Key Compromised
- Classification: Key Compromise
- Target: CEX
Recommended actions
- Check Bitget's official status page and announcements before depositing or withdrawing
- Do not send funds to deposit addresses shared outside the official app or website
- Beware of follow-on phishing: ignore unofficial "refund", "recovery", or "claim" links and DMs; use the project's verified channels only
Source & attribution
This 0xCERT advisory relays an incident recorded in the DeFiLlama hacks database (https://defillama.com/hacks). Figures are preliminary estimates and may be revised; refer to the project's own post-mortem for the authoritative record. Report additional details to 0xCERT at https://www.0xcert.com/report.
Indicators of compromise
All IOC feeds →- address0x770b10b273fc44fe9197d6bf20f145c2e98463eePrimary attacker-controlled receiving address, EVM (Bitget) · Ethereum
- addressTBWNguTTgezw9dVorX441C6nDrZpRxYwKDPrimary attacker-controlled receiving address (Bitget) · Tron
- addressrwNhefsz1UQEusxhCvHip3RANinWi4CTckPrimary attacker-controlled receiving address (Bitget) · XRP Ledger
- addresst1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVGPrimary attacker-controlled receiving address (Bitget) · Zcash
OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.
Published 2026-09-24 · last updated 2026-10-08
curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0147/signed.txt | gpg --verify