Bitget Hack: How On-Chain Analysis Helped Track $190M+ in Real Time
On September 24, 2026, cryptocurrency exchange Bitget suffered a major security breach that ultimately affected approximately $351.6 million in digital assets, according to the exchange. Bitget temporarily suspended withdrawals while it investigated the incident, while saying that customer funds remained safe and that the loss would be covered by its own funds. (Reuters)
The incident also demonstrated the value of real-time blockchain monitoring. Before Bitget publicly confirmed the breach, unusual transfers from wallets associated with the exchange were already visible on-chain. Bubblemaps was among the teams that alerted the public to the activity and continued tracking the movement of funds as the situation developed. (Decrypt)
The first signs appeared on-chain

Bitget says its security systems detected unauthorized transfers from a limited number of hot wallets at 18:31 UTC on September 24. The exchange subsequently suspended withdrawals as a precaution.
But blockchain data provided an earlier indication that something unusual was happening.
Bubblemaps publicly flagged that approximately $180 million in assets had moved from Bitget-associated wallets across multiple chains into a single destination address. As additional transfers were identified, that figure increased to roughly $190 million.
The initial on-chain picture ultimately covered approximately 15 transfers involving seven assets, worth close to $192 million, with ETH representing about 44.4% of the tracked value.
This is where on-chain analytics becomes particularly useful during an active incident. Rather than waiting for an exchange, law enforcement agency, or security company to publish a statement, analysts can observe blockchain activity as it happens and identify relationships between addresses, assets and transactions.
Following the money across chains
The attacker did not simply move one asset from one wallet to another.
The observed activity involved multiple assets and networks, including Ethereum, Arbitrum, BNB Chain, Avalanche and the XRP Ledger. Bitget later confirmed that affected assets included ETH, XRP, BNB, AVAX, USDT and USDC. The Hacker News
One particularly notable transaction involved a newly created wallet that received approximately $19.67 million in USDT0 originating from a Bitget wallet and used it to acquire roughly 7,111 ETH on Arbitrum within six minutes. The swaps were executed through UniswapX and 1inch Fusion, with the buyer reportedly paying a premium in the process.
This type of activity illustrates why wallet analysis is important during a crypto incident. Looking at an individual transaction can provide only a small part of the picture. Following the connected addresses and subsequent movements can reveal how funds are being consolidated, split, swapped and bridged.
Why wallet clustering matters
Blockchain addresses are pseudonymous, but their transaction histories are public. When several addresses exhibit meaningful connections, analysts can investigate whether they may belong to the same entity or form part of the same operational flow.
This is the foundation of wallet clustering.
For incident responders, wallet clusters can help transform thousands of individual transactions into a more understandable picture. Instead of examining every transfer independently, analysts can group related addresses and follow the flow of funds through the broader network.
That makes token holder analysis and wallet clustering particularly valuable when an attacker starts dispersing stolen assets across multiple addresses.
It also explains why visual approaches to blockchain data can be useful. A transaction graph can make relationships between wallets immediately apparent, helping analysts move from individual transactions toward a broader understanding of the operation.
For blockchain investigations, this kind of visualization can be one of the best analytical tools for quickly communicating complex wallet relationships, particularly when an incident is unfolding in real time.
Bubblemaps' role in the Bitget incident
The Bubblemaps team helped alert the public on X and track the movement of the funds in real time, providing an evolving picture as more transfers became visible.
On-chain analysis can reveal what is happening to assets on a public blockchain, but it does not necessarily reveal how an attacker gained access to an exchange's internal systems.
In Bitget's case, the exchange later said that the attacker had compromised a critical backend system within its wallet infrastructure, spoofed transaction data and triggered the authorization process to move funds. Bitget said private-key compromise had not been identified as the cause, and that its investigation into the specific intrusion method was ongoing.
The $351.6 million figure
The incident also highlights an important limitation of real-time blockchain monitoring.
The first publicly visible transfers did not account for the full amount that Bitget ultimately reported as affected.
Bubblemaps' early tracking identified approximately $180 million, later rising to around $190 million and approximately $192 million as more transfers were identified. Bitget subsequently reported $351.6 million in affected assets.
Other blockchain investigations subsequently identified additional movements, including substantial XRP holdings on the XRP Ledger that were not captured by some of the initial Ethereum-focused tracking.
This gap is an important reminder that wallet analytics during an active exploit are necessarily provisional. Asset prices change, labels can be incomplete, cross-chain movements can complicate attribution, and some transactions may not initially be connected to the incident.
Real-time on-chain analysis is therefore less about producing a final number immediately and more about continuously updating the picture as new evidence appears.
Who was behind the attack?
Bitget CEO Gracy Chen has said that preliminary findings point toward a North Korean threat actor.
According to Chen, investigators observed IP addresses that matched VPN choices associated with a North Korean group. She also said the attack method showed similarities to known North Korean hacking operations. The Hacker News reported the same claims, while noting that Bitget's investigation was still ongoing. The Hacker News+1
The attribution should therefore be treated as suspected rather than conclusively established at this stage. Bitget has said that a fuller technical investigation is underway.
What the Bitget incident shows about blockchain investigations
The Bitget hack is a useful example of why public blockchains can provide an important layer of visibility during a security incident.
An exchange's internal systems may be compromised, but once assets move on-chain, those movements can become observable to researchers around the world.
Through on-chain analytics, investigators can:
- Identify unusual transfers from known exchange wallets
- Perform token holder analysis to understand where assets are moving
- Use wallet clustering to identify related addresses and transaction flows
- Conduct wallet analysis across multiple chains
- Track stolen assets as they are swapped, bridged or dispersed
- Communicate emerging threats while an incident is still unfolding
In the Bitget case, the first public on-chain estimates were incomplete, but they provided an early indication that something significant was happening. As the investigation progressed, researchers were able to follow the funds while Bitget worked to contain the breach.
For Bubblemaps, this is precisely where blockchain visualization and investigation can add value. The objective is not to claim that a visual map alone explains an exploit. It is to make complex blockchain activity easier to understand, investigate and communicate when every minute matters.
The blockchain does not tell you everything about a hack. But it can show you where the money goes.