Bitget attacker tested risk controls with small transfers before $388 million theft, CEO says
Bitget CEO Gracy Chen revealed on Tuesday that the hacker who stole nearly $388 million from the exchange first conducted two small test transfers to verify the platform’s risk controls. According to…
Bitget CEO Gracy Chen revealed on Tuesday that the hacker who stole nearly $388 million from the exchange first conducted two small test transfers to verify the platform’s risk controls. According to Chen, these initial probes occurred approximately thirty minutes before the massive drain on the exchange’s hot wallet. This disclosure offers a rare glimpse into the operational mechanics of high-stakes crypto heists, suggesting that sophisticated attackers now treat security protocols like a sandbox environment before executing large-scale thefts. The revelation underscores a growing trend in digital asset crimes where attackers meticulously map out technical boundaries to ensure their primary exploit remains undetected until the final moment.
The incident, which occurred in February 2025, initially sent shockwaves through the cryptocurrency market, causing a temporary dip in Bitcoin prices as traders feared broader contagion. Bitget is one of the largest centralized exchanges globally, serving millions of users and managing billions in assets. The breach was traced to a vulnerability in the exchange’s internal hot wallet, which holds liquid assets for immediate customer withdrawals. Unlike previous hacks that targeted third-party infrastructure or smart contracts, this attack struck the core of the exchange’s own custody system. Chen stated that the team identified the anomaly within minutes and immediately froze transactions to prevent further loss. The speed of the response was critical in containing the damage, as the remaining funds were quickly moved to cold storage, which is offline and significantly harder to access.
In the aftermath, Bitget has committed to covering the full value of the stolen funds, promising to maintain user balances and liquidity without disruption. This pledge is a standard practice in the industry, designed to preserve user confidence and prevent a bank-run scenario. However, the financial burden of such a breach is immense, potentially impacting the company’s operational budget and future growth initiatives. Security experts note that the attacker’s method mirrors techniques seen in other major breaches, such as the 2022 Ronin Network hack, where small test transactions were used to bypass alert thresholds. This pattern suggests that centralized exchanges must evolve their monitoring systems to detect not just volume spikes, but also the specific behavioral signatures of reconnaissance activities.
Looking ahead, the incident is likely to accelerate regulatory scrutiny on how centralized exchanges manage hot wallets. Regulators in the US and Europe have been pushing for stricter capital requirements and mandatory insurance for digital asset custodians. Bitget’s response will be closely watched by both competitors and authorities as a benchmark for crisis management. The company has also announced it is working with law enforcement and blockchain analytics firms to track the stolen funds. While the likelihood of recovering the full amount remains uncertain, the detailed timeline provided by Chen offers vital data for the broader security community. This event serves as a stark reminder that in the decentralized world of crypto, the centralized points of failure remain the most attractive targets for organized cybercriminals.
Read Full Story at The Block →

