GoPlus Says Bitget Attack Broke Transaction-Signing Trust Chain
The $387.5 million incident involved compromised wallet back-end systems and falsified transaction data, not a private-key leak, GoPlus said.

GoPlus Security said the $387.5 million attack on Bitget compromised the exchange’s transaction-signing trust chain, allowing unauthorized transfers without exposing private keys.
The attacker breached key wallet back-end systems, falsified transaction data and induced Bitget’s authorization process to generate valid signatures for transfers it did not intend to approve, GoPlus said.
The movement of funds lasted about two hours and 25 minutes. The largest wave transferred roughly $185 million in assets within about one minute.
GoPlus Security has blacklisted addresses linked to the attacker and shared them with ecosystem partners. It also identified structural similarities between the incident and the 2025 attack on Bybit, while the initial entry point remains unconfirmed.
Bitget has not published a complete technical report on the incident.


