تعرضت منصة تداول العملات المشفرة «بيتغيت» (Bitget) لهجوم إلكتروني أدى إلى تحويل أصول رقمية بقيمة نحو 387.5 مليون دولار إلى عناوين يسيطر عليها المهاجمون، في أكبر سرقة للعملات المشفرة من حيث القيمة المسجلة خلال عام 2026 حتى الآن، وفق شركة الاستخبارات الأمنية المتخصصة في البلوك تشين «TRM Labs».
ورفعت المنصة تقديرها الأولي للخسائر من 351.6 مليون دولار إلى 387.5 مليون دولار، موضحة أن المراجعة اللاحقة شملت أصولاً إضافية على شبكتي Zcash وTRON لم تكن مدرجة في التقدير الأول.
وأكدت «بيتغيت» أن التعديل لا يمثل عملية اختراق جديدة، وإنما تقديراً أكثر اكتمالاً للأصول المتأثرة بالحادثة نفسها.
كيف بدأ اختراق «بيتغيت»؟
رصدت أنظمة «بيتغيت» تحويلات غير مصرح بها من بعض المحافظ الساخنة والدافئة عند الساعة 18:31 بتوقيت غرينتش في 24 سبتمبر 2026، لتفعّل المنصة إجراءات الاستجابة للحوادث وتوقف عمليات السحب مؤقتاً كإجراء احترازي.
وبحسب الشركة، بقيت المحافظ الباردة، التي تحتفظ بالجزء الأكبر من أصول المنصة، خارج نطاق الهجوم.
وقالت «بيتغيت» إن المهاجمين لم يسرقوا المفاتيح الخاصة، وإنما استغلوا ثغرة في بنية النظام الخلفية المرتبطة بالمحافظ، وتمكنوا من التلاعب ببيانات أوامر السحب وخداع آلية التفويض بحيث بدت المعاملات غير المشروعة وكأنها عمليات مصرح بها.
وفي تحديث رسمي لاحق، قالت المنصة إنها حددت مسار الهجوم والثغرة التي استُغلت، وإنها عالجت الخلل، بينما شاركت شركتا Mandiant وSlowMist في التحقيقات الأمنية.
ما حجم الأموال المسروقة؟
وبلغت القيمة التي أعلنت عنها «بيتغيت» نحو 387.5 مليون دولار، مقارنة بتقدير أولي بلغ 351.6 مليون دولار.
وشملت الأصول المتأثرة XRP وETH وUSDT وZEC وUSDC وUSDT0 وXAUt وBNB وAVAX وTRX، وانتقلت عبر عدة شبكات، من بينها إيثيريوم، وشبكات متوافقة معها، وXRP Ledger، وZcash، وTRON.
وأظهرت بيانات TRM Labs أن جزءاً كبيراً من الأموال جرى تقسيمه على محافظ جديدة خلال فترة قصيرة، بينما تحركت أجزاء أخرى عبر بروتوكولات وخدمات مختلفة بهدف نقل الأصول بين الشبكات وتحويلها إلى عملات أخرى.
وكانت عملة XRP من أكبر الأصول المتأثرة، إذ رصدت TRM Labs خروج ما يقارب 158 مليون دولار من القيمة عبر XRP Ledger في بداية تتبعها للحادثة، كما انتقلت أجزاء من الأصول عبر THORChain وغيرها من خدمات الربط والتبادل بين الشبكات.
هل استخدم القراصنة منصات لامركزية لإخفاء الأموال؟
تشير تحليلات المعاملات على السلسلة إلى أن المهاجمين تحركوا بسرعة لتوزيع الأموال على عناوين متعددة وتحويل بعض الأصول إلى عملات أخرى.
ورصدت TRM Labs مسارات استخدمت فيها أصول على شبكات مختلفة، بينها BNB Chain وإيثيريوم وTRON، قبل انتقال أجزاء منها عبر THORChain إلى شبكة بيتكوين. كما ظهرت معاملات عبر خدمات وجسور أخرى بين الشبكات.
ويجعل هذا النمط عملية استرداد الأموال أكثر تعقيداً، لكنه لا يعني بالضرورة اختفاءها؛ إذ تظل حركة الأصول على شبكات البلوك تشين قابلة للتتبع، ويمكن لمنصات التداول ومصدري العملات المستقرة وشركات تحليل البلوك تشين التعاون لتحديد العناوين المرتبطة بالأموال المسروقة وتجميدها عندما يكون ذلك ممكناً.
هل تقف كوريا الشمالية وراء الاختراق؟
وبرز احتمال ارتباط الهجوم بجهات قرصنة مرتبطة بكوريا الشمالية، لكن هذا الإسناد لم يُحسم نهائياً.
وقالت الرئيسة التنفيذية لـ«بيتغيت»، غرايسي تشين، إن المؤشرات الأولية تجعل ضلوع جهات كورية شمالية احتمالاً قوياً، مستندة إلى مؤشرات مرتبطة بعناوين الإنترنت وأنماط النشاط التي رصدها المحققون.
وأشارت TRM Labs بدورها إلى مؤشرات تتوافق مع أنماط مرتبطة بعمليات سرقة سابقة نُسبت إلى جهات كورية شمالية، لكنها لم تقدم هذا الإسناد باعتباره حقيقة نهائية.
لذلك، فإن تحديد الجهة المسؤولة عن الهجوم يظل جزءاً من التحقيقات الجارية، ولا سيما مع استمرار تتبع الأموال عبر عدة شبكات.
هل خسر مستخدمو «بيتغيت» أموالهم؟
أكدت «بيتغيت» أن أرصدة المستخدمين لم تتأثر، وأن المحافظ الباردة بقيت آمنة، وقالت المنصة إن الخسائر الناجمة عن الحادث ستُغطى من صندوق حماية المستخدمين الذي تتجاوز قيمته 464 مليون دولار، وهو ما يفوق قيمة الأصول المتأثرة التي أعلنتها الشركة. كما أكدت أن تعليق عمليات السحب كان إجراءً أمنياً احترازياً وليس نتيجة نقص في السيولة.
واستمرت عمليات الإيداع والتداول، بينما ظلت عمليات السحب معلقة خلال مرحلة التحقق الأمني.
متى تعود عمليات السحب؟
أعلنت «بيتغيت» خطة تدريجية لاستعادة عمليات السحب، تبدأ في 28 سبتمبر، بعد الانتهاء من اختبارات الأمان والتحقق من سلامة البنية التحتية.
وبحسب الجدول المعلن، بدأت عودة سحب بيتكوين في 28 سبتمبر، على أن يتبعها إيثيريوم في 29 سبتمبر، ثم USDT في 30 سبتمبر، بينما تستكمل عمليات السحب لبقية الأصول والخدمات الأخرى في 2 أكتوبر، وفق نتائج اختبارات الأمان لكل مرحلة.
«بيتغيت» تطلق مكافأة لاستعادة الأموال
إلى جانب تجميد العناوين المرتبطة بالاختراق والتعاون مع شركات الأمن والمنصات الأخرى، أطلقت «بيتغيت» برنامج مكافآت للمساعدة في استعادة الأموال.
وقالت الشركة إن البرنامج يوفر مكافأة تعادل 5% من الأموال التي ينجح طرف في تجميدها أو استعادتها، وفق شروط البرنامج، مشيرة إلى أن بعض الأصول المتأثرة جرى تجميدها بالفعل نتيجة التعاون مع جهات مختلفة في قطاع العملات المشفرة.
ماذا يكشف اختراق «بيتغيت»؟
تتجاوز دلالة الحادث قيمة الأموال المسروقة، إذ يكشف أن حماية منصات العملات المشفرة لا تتوقف عند تأمين المفاتيح الخاصة.
ففي حالة «بيتغيت»، تقول المنصة إن المهاجمين لم يحصلوا على المفاتيح الخاصة، وإنما استهدفوا الطبقة البرمجية المسؤولة عن إعداد المعاملات وتمريرها إلى نظام التفويض.
ويبرز ذلك أهمية حماية الأنظمة الخلفية، والفصل بين طبقات البنية التحتية، وإجراء عمليات تحقق مستقلة من أوامر السحب، إلى جانب مراقبة التحويلات غير المعتادة في المحافظ الساخنة.
كما توضح الحادثة التحديات التي تواجه عمليات استرداد العملات المشفرة بعد خروجها من محافظ المنصة، إذ يمكن نقل الأصول بسرعة بين شبكات متعددة وتحويلها إلى رموز أخرى، ما يجعل التعاون بين منصات التداول وشركات الأمن ومشغلي الشبكات والجهات المختصة عاملاً أساسياً في محاولة تجميد الأموال واستعادتها.
وتواصل «بيتغيت» التحقيق في الحادثة بالتعاون مع جهات أمنية وشركتي Mandiant وSlowMist، بينما يستمر تتبع الأصول على السلسلة لتحديد الأموال التي يمكن تجميدها أو استردادها. وتبقى التفاصيل الكاملة للهجوم ونسبة الأموال التي يمكن استعادتها قيد التحقيق.
The cryptocurrency trading platform “Bitget” was subjected to a cyber attack that resulted in the transfer of digital assets worth approximately $387.5 million to addresses controlled by the attackers, marking the largest cryptocurrency theft by recorded value in 2026 so far, according to the blockchain security intelligence firm “TRM Labs”.
The platform raised its initial loss estimate from $351.6 million to $387.5 million, clarifying that the subsequent review included additional assets on the Zcash and TRON networks that were not listed in the initial estimate.
Bitget confirmed that the adjustment does not represent a new breach, but rather a more complete assessment of the assets affected by the incident.
How did the Bitget hack begin?
Bitget’s systems detected unauthorized transfers from some hot and warm wallets at 18:31 GMT on September 24, 2026, prompting the platform to activate incident response procedures and temporarily halt withdrawals as a precautionary measure.
According to the company, the cold wallets, which hold the majority of the platform’s assets, remained unaffected by the attack.
Bitget stated that the attackers did not steal the private keys but exploited a vulnerability in the backend architecture associated with the wallets, allowing them to manipulate withdrawal order data and deceive the authorization mechanism so that the illicit transactions appeared to be authorized.
In a subsequent official update, the platform indicated that it had identified the attack vector and the exploited vulnerability, and that it had addressed the flaw, while companies Mandiant and SlowMist participated in the security investigations.
What is the size of the stolen funds?
The value announced by Bitget was approximately $387.5 million, compared to an initial estimate of $351.6 million.
The affected assets included XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX, and TRX, and they were transferred across several networks, including Ethereum, compatible networks, XRP Ledger, Zcash, and TRON.
Data from TRM Labs showed that a large portion of the funds was divided among new wallets within a short period, while other portions moved through various protocols and services to transfer assets between networks and convert them into other currencies.
XRP was one of the largest affected assets, with TRM Labs tracking approximately $158 million in value exiting via XRP Ledger at the beginning of its investigation into the incident, with portions of the assets also moving through THORChain and other cross-network bridging and exchange services.
Did the hackers use decentralized platforms to hide the funds?
Transaction analyses on the chain indicate that the attackers quickly moved to distribute the funds across multiple addresses and convert some assets into other currencies.
TRM Labs tracked pathways where assets were used across different networks, including BNB Chain, Ethereum, and TRON, before portions were transferred via THORChain to the Bitcoin network. Transactions also appeared through other services and bridges between networks.
This pattern complicates the recovery of funds, but it does not necessarily mean they have disappeared; the movement of assets on blockchain networks remains traceable, and trading platforms, stablecoin issuers, and blockchain analysis companies can collaborate to identify addresses linked to the stolen funds and freeze them when possible.
Is North Korea behind the hack?
The possibility of the attack being linked to hacking entities associated with North Korea has emerged, but this attribution has not been definitively confirmed.
Bitget’s CEO, Gracy Chen, stated that initial indicators make the involvement of North Korean entities a strong possibility, based on indicators related to IP addresses and activity patterns observed by investigators.
TRM Labs also pointed to indicators consistent with patterns linked to previous thefts attributed to North Korean entities, but it did not present this attribution as a definitive fact.
Therefore, identifying the party responsible for the attack remains part of ongoing investigations, especially as the tracking of funds continues across multiple networks.
Did Bitget users lose their money?
Bitget confirmed that user balances were unaffected, and that cold wallets remained secure, stating that the losses resulting from the incident will be covered by the user protection fund, which exceeds $464 million, surpassing the value of the affected assets reported by the company. It also confirmed that the suspension of withdrawals was a precautionary security measure and not a result of liquidity shortages.
Deposits and trading continued, while withdrawals remained suspended during the security verification phase.
When will withdrawals resume?
Bitget announced a phased plan to restore withdrawals, starting on September 28, after completing security tests and verifying the integrity of the infrastructure.
According to the announced schedule, Bitcoin withdrawals began on September 28, followed by Ethereum on September 29, and then USDT on September 30, while withdrawals for the remaining assets and other services will be completed on October 2, depending on the results of security tests for each phase.
Bitget launches a reward program for recovering funds
In addition to freezing addresses linked to the hack and collaborating with security firms and other platforms, Bitget launched a reward program to assist in recovering the funds.
The company stated that the program offers a reward equivalent to 5% of the funds successfully frozen or recovered by a party, according to the program’s terms, noting that some of the affected assets have already been frozen as a result of cooperation with various entities in the cryptocurrency sector.
What does the Bitget hack reveal?
The significance of the incident goes beyond the value of the stolen funds, revealing that the protection of cryptocurrency platforms does not stop at securing private keys.
In the case of Bitget, the platform states that the attackers did not obtain the private keys but targeted the software layer responsible for preparing transactions and passing them to the authorization system.
This highlights the importance of securing backend systems, separating infrastructure layers, conducting independent verifications of withdrawal orders, and monitoring unusual transfers in hot wallets.
The incident also illustrates the challenges of recovering cryptocurrency once it has exited the platform’s wallets, as assets can be quickly moved across multiple networks and converted into other tokens, making collaboration between trading platforms, security firms, network operators, and regulatory authorities a crucial factor in attempts to freeze and recover funds.
Bitget continues to investigate the incident in collaboration with security entities and companies Mandiant and SlowMist, while the tracking of assets on the chain continues to identify funds that can be frozen or recovered. The full details of the attack and the proportion of funds that can be recovered remain under investigation.


