Bitget-linked actor withdrew $1.23M from Binance then returned funds 入门

Bitget-linked actor withdrew $1.23M from Binance then returned funds

2026-09-26 · PANews · source
入门下载费率

Quick answer

A hacker associated with Bitget is suspected of withdrawing $1.23 million in cryptocurrency from Binance on or before 2026-09-26, according to PANews reporting dated that day. The funds were transferred to an external address and subsequently moved back to the same origin address — not to Binance’s treasury or insurance fund. This sequence suggests neither a successful theft nor a standard hot-wallet breach, but rather an anomalous withdrawal enabled by compromised credentials or misconfigured permissions. No user funds held directly on Binance appear to have been lost, though the incident highlights structural ambiguities in how exchanges assign wallet ownership and attribute transaction intent.

What actually happened — and what we know for sure

On or before 2026-09-26, an unidentified actor withdrew $1.23 million worth of digital assets from Binance’s infrastructure, per PANews’ on-chain analysis published that date. The transaction originated from an address later linked by analysts to Bitget-associated infrastructure — though no official statement from Bitget or Binance has confirmed this association. Crucially, the full $1.23 million was routed back to the same originating address within minutes. That return did not go to Binance’s known cold storage or recovery wallets; it landed at the hacker’s original address. There is no public evidence that the funds entered user-facing balances, were swapped, or interacted with DeFi protocols. The source does not specify asset composition, time zone, or block height — only the dollar-equivalent value and directionality of movement.

How this affects market participants and asset stability

This event does not reflect a loss of user-held assets on Binance — no withdrawals from user accounts or hot wallets are documented in the source. However, it exposes ambiguity in how custodial platforms define ‘control’. If the withdrawn address was under Bitget’s operational oversight (e.g., a shared custody vault or cross-exchange settlement channel), the incident signals a failure in access governance — not just technical security. For stablecoin holders, the lack of arbitrage-triggering price slippage suggests the movement involved non-trading assets or occurred off major order books. For BTC and ETH holders, the episode reinforces that exchange-linked wallet clusters remain high-value forensic targets — even when no net outflow occurs. It also complicates regulatory reporting: if the address belongs to Bitget, Binance may face questions about counterparty KYC; if it belongs to a third-party liquidity provider, jurisdictional responsibility fractures further.

Why the data口径 and attribution remain uncertain

The $1.23 million figure comes exclusively from PANews’ valuation as of 2026-09-26 — no on-chain explorer timestamp, USD stablecoin pair, or exchange-rate methodology is cited. The label “Bitget hacker” is descriptive, not forensic: PANews notes the address appeared in prior Bitget-related transaction clusters but provides no chain-of-custody proof (e.g., contract deployments, multisig signers, or domain verification). Binance has not issued a statement. Bitget has not acknowledged involvement. Neither exchange has updated its security page or published wallet rotation logs. Without wallet ownership attestation or signed transaction metadata, the ‘hacker’ designation rests on behavioral clustering — a method prone to false positives when exchanges share infrastructure or reuse addresses across services.

Frequently asked questions

Q: Did Binance lose money or freeze user withdrawals after this event? A: No. The source reports no suspension of deposits, withdrawals, or trading services on Binance following the incident. The $1.23 million never left the originating address’s control — it cycled internally. There is no indication of user balance adjustments or insurance fund activation.

Q: Is this related to Bitget’s 2024 wallet compromise or the 2025 API key leak? A: Not confirmed. PANews does not reference prior incidents in its 2026-09-26 report. The address linkage is based solely on on-chain adjacency, not code reuse, signature patterns, or reused seed phrases. Without forensic correlation, treating this as a continuation of earlier events would be speculative.

Risk warning and disclosure

Cryptocurrency investments involve substantial risk, including total loss of principal. This article reports publicly available information from PANews as of 2026-09-26 and does not constitute financial, legal, or tax advice. We do not hold positions in Binance, Bitget, or associated tokens. Some links in this article direct to internal resources such as our Glossary and news hub; these are for contextual reference only. The /go/binance-download/ link is an affiliate referral path — we receive compensation if users complete verified downloads through it. Past performance does not indicate future results.

Risk warning and disclosure

This article is independent third-party information, not an official publication, and is not investment advice.

Related News

Follow the market on a major exchange

Download Binance or OKX from the official website to start trading.

Risk warning: crypto prices are volatile. This page is for information only and is not investment advice.
Download Binance App Download OKX App