Lookonchain flags wallet that withdrew ETH from Binance before sending funds to Bitget hacker address

Lookonchain flags wallet that withdrew ETH from Binance before sending funds to Bitget hacker address

N
News Editor
2026-09-26 06:12:24
A new on-chain transfer has drawn attention in the aftermath of the Bitget hack. According to Lookonchain, a wallet beginning with 0x4885 withdrew 257.6 ETH, worth about $692,000, and 545,000 USDT from Binance around 11 hours earlier. The wallet then swapped the USDT for 200.2 ETH and, roughly an hour before the post, sent a total of 457.9 ETH, or about $1.23 million, to a wallet tied to the Bitget hacker. Lookonchain said the wallet "appears" to be related, but no independent confirmation has been provided so far. The transfer path stands out because it runs opposite to the pattern usually seen in exchange hacks, where stolen funds are moved out of the victim platform, swapped on decentralized venues, and spread across chains. Here, the funds were first withdrawn from a KYC exchange and then sent into the hacker-linked address. The report also revisits the broader Bitget breach, whose estimated losses were revised from $351.6 million to $387.5 million, and notes that Bitget has pledged to cover the losses with its user protection fund while investigations continue.

New on-chain activity has emerged in the Bitget hack case. According to a post from blockchain analytics account Lookonchain, a wallet starting with 0x4885 withdrew 257.6 ETH, worth about $692,000, and 545,000 USDT from Binance around 11 hours earlier. It then swapped the USDT for 200.2 ETH and, about an hour before the post, transferred a total of 457.9 ETH, or roughly $1.23 million, into a wallet associated with the Bitget hacker.

Lookonchain said the wallet "appears" to be linked to the attacker. No other confirmation has been provided so far to establish a direct connection between the 0x4885 wallet and the hacker.

An unusual funding route

The transfer pattern runs against the direction more commonly seen in hack cases. In many incidents, attackers move stolen assets out of the victim platform, swap them through decentralized exchanges, and scatter the proceeds across multiple chains. In this case, the 0x4885 wallet first withdrew funds from Binance, a centralized exchange with KYC requirements, and then sent the assets to the hacker wallet.

ABMedia said several explanations remain possible. The wallet could belong to the attacker or an accomplice and have been used to top up gas or consolidate funds. It could also be an attempt by a third party to create confusion. Relative to the total losses in the Bitget incident, the $1.23 million transfer is small. Still, if the wallet is eventually confirmed to be tied to the attacker, account information on Binance could become a useful lead for investigators. As of publication, Binance had not issued a public response.

Bitget loss estimate revised to $387.5 million

According to Crypto Briefing, Bitget detected unauthorized transfers from its hot and warm wallets at 18:31 UTC on Sept. 24, 2026, and then suspended all withdrawals. The initial estimated loss was $351.6 million. That figure was later revised upward to $387.5 million.

The revision included ZEC and TRX. Bitget said it had not found any other unauthorized outflows.

As for the attack method, the attacker did not steal private keys. Instead, the exploit abused a flaw in Bitget's backend wallet system to forge transaction authorization data and bypass standard verification checks. Cold wallets were not affected. Lookonchain had previously said the attacker had already converted most of the stolen assets on EVM chains into 67,982 ETH.

Investigation, attribution questions, and the protection fund

Bitget CEO Gracy Chen said the attack points to a North Korean hacking group based on IP behavior patterns and on-chain analysis. At the same time, the report said some analysts remain cautious about directly attributing the incident to Lazarus Group. Bitget and outside investigators, however, believe the attack characteristics match those of a North Korean state-backed operation.

Cybersecurity firms Mandiant and SlowMist have joined the investigation, and law enforcement agencies have been notified.

Bitget has pledged to absorb the losses in full through its user protection fund. The fund consists of 5,500 BTC and is valued at about $464 million. The current loss estimate equals about 83.5% of that amount. On that basis, the remaining buffer is about $76.5 million, before accounting for any assets that may later be recovered. Because the fund is denominated in bitcoin, that buffer will also move with the BTC price.

On the recovery side, Bitget has launched a bounty program. Parties that proactively freeze the attacker's funds can receive a 5% reward, and those that help recover assets can also receive 5%. The exchange has also published the attacker's addresses and a live tracking dashboard. Trading and deposits are operating normally, while withdrawals remain pending until system verification is completed.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.