Bitget's CEO confirmed that the attacker who drained approximately $388 million from the exchange conducted two small test transfers roughly thirty minutes before executing the full theft. The probe transfer technique suggests the attacker was mapping withdrawal controls, approval thresholds, or monitoring latency before committing to the large transaction. The incident is among the largest exchange thefts of 2026.
For Armada's crypto-repo desk, the attack pattern is operationally relevant because Armada's custody partner Fireblocks uses policy engine rules and transaction velocity controls to gate withdrawals. The Bitget case illustrates that adversaries specifically probe for detection gaps before large movements. Armada should verify with Fireblocks that its policy engine flags or blocks sequences of anomalous low-value transactions followed by large outflows, and confirm this is within SOC 2 control scope.