Key facts
- Over 600 wallets suspected to be linked to GoMining were drained on September 4, 2026.
- The total estimated loss from the hack is approximately $2.8 million.
- A significant portion of the stolen funds originated from a single service wallet associated with GoMining.
- Stolen assets were consolidated into approximately 1,147 ETH after being bridged across multiple chains.
- Bitget suspended deposits and withdrawals for GOMINING-ETH following the incident.
On September 4, 2026, a coordinated exploit targeted over 600 wallets associated with the GoMining platform, resulting in an estimated loss of $2.8 million. On-chain monitor Specter identified the attack, noting that a single service wallet linked to GoMining accounted for nearly the entire sum. The remaining losses were spread across more than 600 other addresses, many of which had previously held GoMining's native token, GMT.
Attackers swiftly moved the stolen assets, swapping them across different cryptocurrencies and bridging them across multiple blockchains before consolidating approximately 1,147 ETH. This cross-chain movement is a common tactic to obscure the trail of illicit funds.
The incident has raised questions about user self-custody versus platform infrastructure security. Following the exploit, Bitget announced on September 5, 2026, that it was suspending deposits and withdrawals for GOMINING-ETH, citing wallet maintenance. A GoMining ambassador account on X also confirmed that withdrawals were blocked and that the GMT token had experienced a sell-off.
This event aligns with a broader pattern of similar exploits observed in 2026, where attackers have used fast, multi-chain consolidation into ETH as an exit strategy. GoMining, which has recently expanded its product offerings to include NFT miners and payment solutions, has yet to issue an official statement regarding the alleged hack.