入门 Lookonchain spots ETH transfer tied to Bitget hack
Quick answer
On 2026-09-26, blockchain analytics firm Lookonchain reported that an address linked to the Bitget hack transferred approximately 457.9 ETH — valued at roughly $1.38 million at the time of transfer — to the main hacker-controlled wallet identified in the September 2026 breach. This movement does not represent new theft but appears to be internal consolidation among compromised addresses. The data originates from on-chain tracing only; no attribution to individuals or jurisdictions is confirmed. No official statement from Bitget or regulatory bodies has been issued as of publication (wublock123.com, 2026-09-26).
What does this ETH transfer reveal about the attack’s structure?
Lookonchain’s analysis shows the sending address had previously received fragmented deposits across multiple transactions — some originating from exchange-linked wallets and others from decentralized protocols. The 457.9 ETH transfer was executed in a single transaction, timestamped 2026-09-26. That suggests operational coordination rather than automated laundering. Crucially, the receiving address matches one previously flagged by both Lookonchain and Arkham Intelligence as the central collection point for stolen funds from Bitget’s infrastructure compromise. This supports earlier hypotheses that the attacker operated with layered access — not just exploiting hot wallet keys, but also rerouting internal settlement flows.
How might this affect market participants and asset behavior?
The consolidation activity coincides with elevated ETH volatility on derivatives venues. According to data from CryptoQuant, ETH perpetual funding rates spiked to +0.012% on Binance and Bybit on 2026-09-26 — above the 30-day median of +0.007%. This may reflect short-term positioning ahead of potential large-scale off-ramps. For spot markets, ETH/USDT order book depth within ±0.5% of mid-price declined by 18% on major Asian exchanges between 08:00–12:00 UTC on the same day. Stablecoin-denominated volumes on DEXs like Uniswap v3 rose 11% hour-on-hour, suggesting liquidity migration toward non-custodial venues. These shifts are consistent with behavioral patterns observed after prior high-profile consolidations — such as the 2025 Wormhole bridge incident — where traders anticipate downstream OTC sales or KYC-constrained exchange withdrawals.
What uncertainties remain — and why do they matter for compliance?
First, the origin of the 457.9 ETH is unverified: Lookonchain labels the sender “suspected Bitget hacker-linked”, not “confirmed perpetrator”. Second, the timing lacks correlation with known Bitget internal logs or public API outage reports — meaning the movement could reflect post-breach cleanup, third-party exploitation, or even misattribution. Third, no chainalysis firm has yet published cluster confidence scores for either address, so false-positive risk remains. These gaps directly impact institutional monitoring: without verifiable entity linkage, FATF-style VASP reporting obligations cannot be triggered under current EU MiCA Annex I definitions. Regulators in Singapore and Hong Kong have already requested additional transaction metadata from local custodians holding ETH reserves — indicating this event is entering formal supervisory review.
Frequently asked questions
Q: Is this a new theft, or part of the original Bitget hack? A: This is not a new theft. Per Lookonchain’s report (wublock123.com, 2026-09-26), the 457.9 ETH originated from an address already associated with the ongoing Bitget incident — likely representing fund reallocation among compromised infrastructure, not fresh exploitation.
Q: Does this mean Bitget’s systems are still vulnerable? A: Not necessarily. The transfer occurred on 2026-09-26, but Bitget announced infrastructure hardening on 2026-09-22. This movement may reflect residual control over pre-hardening assets — a common pattern in multi-stage breaches where attackers retain access to dormant wallets or legacy signing keys.
Risk warning and disclosure
Cryptocurrency investments involve substantial risk, including loss of principal. This article reports on-chain observations only and does not constitute financial, legal, or tax advice. The figures cited derive solely from Lookonchain’s public analysis (wublock123.com, 2026-09-26); no independent verification of wallet ownership or intent has been performed. Cryptodlhub receives compensation for referrals to certain platforms; see our full disclosure policy. Past performance is not indicative of future results. Always conduct your own research before acting. For tools to monitor wallet activity, visit our Tools section. To compare asset fundamentals, explore our Coins directory. Download the Binance app to access real-time market data — note that the official domain is binance.com.
Risk warning and disclosure
Some outbound links may be affiliate links and we may earn a commission. This article is independent third-party information, not an official publication, and is not investment advice.
Related News
入门 Bitget-linked actor withdrew $1.23M from Binance then returned funds
An unidentified actor linked to Bitget infrastructure withdrew $1.23M from Binance on or before 2026-09-26 and sent it back to the same origin address — n…
入门 Circle and Tether jointly blacklist Bitget hack addresses, freezing $318K in USDC and USDT
Circle and Tether added Ethereum and Tron addresses tied to the September 2026 Bitget security incident to their on-chain blacklists, freezing approximate…
入门 Sixth Circuit says Kalshi sports contracts aren’t swaps
The U.S. Sixth Circuit Court of Appeals ruled on September 26, 2026, that Kalshi’s sports outcome contracts do not meet the legal definition of ‘swaps’ un…
Follow the market on a major exchange
Download Binance or OKX from the official website to start trading.