Bitget Confirms $351.6 Million Hot Wallet Hack Spanning Ethereum and Stablecoins
Key Takeaways
- •Bitget suffered an estimated $351.6 million loss after an intruder penetrated its wallet service backend, forged transfer information, and triggered approval signing to drain hot wallets of ETH, USDT, USDC, BNB, and AVAX.
- •The exchange's private keys were not compromised, its cold wallets were unaffected, and containment is complete, according to preliminary findings published by CEO Gracy Chen.
- •All losses fall within Bitget's User Protection Fund, which holds more than $464 million, while withdrawals remain suspended without a committed resumption timeline.
- •Circle and Tether blacklisted an exploiter address, freezing roughly $318,000 in stablecoins, but other attacker wallets still hold more than 63,000 ETH that no issuer can freeze.
- •Traced IP addresses may be associated with a DPRK-linked group, though Bitget emphasized that the attribution has not been definitively established.

Bitget, one of the world's largest cryptocurrency exchanges, has lost more than $350 million after attackers breached its hot wallets — the internet-connected wallets an exchange keeps online to process withdrawals and settlement, and the standard first target in exchange breaches. Hot-wallet compromises have been a recurring entry point in exchange losses, with past incidents at Japan's Coincheck in 2018 and Binance in 2019 both traced to online wallets.
On-chain monitoring tools flagged the first abnormal movements in the early hours of September 25, showing more than $180 million in assets leaving exchange-controlled addresses for wallets with no identified owner. The running total of traced outflows subsequently climbed past $351 million, with the breach first detected by external on-chain analysis rather than the exchange's internal monitoring.
The stolen holdings spanned Ethereum (ETH), the stablecoins USDC and USDT, as well as BNB and AVAX. According to on-chain data, the attackers converted those assets at prices well below prevailing market rates — an extreme demonstration of slippage — before moving the proceeds to other blockchains through bridge protocols, complicating recovery efforts. Reports of failed withdrawal requests from users followed within minutes of the suspicious outflows.
Bitget chief executive Gracy Chen publicly confirmed the incident on Thursday and put the estimated damage at approximately $351.6 million. She stressed that customer funds are safe and that the entire loss falls within the coverage of the exchange's User Protection Fund, which currently holds more than $464 million — enough to absorb the breach in full. Bitget halted withdrawals immediately after detecting the attack and said services will resume only after a complete security review. Chen also disclosed that IP addresses traced during the investigation may be associated with a DPRK-linked group, while emphasizing that the connection has not been definitively established. DPRK-linked hacking clusters have been blamed by United Nations investigators and blockchain-analytics firms for billions of dollars in cryptocurrency thefts in recent years, a track record that makes attribution a central question in any breach of this scale.
Backend Compromised, Private Keys Untouched
Bitget's official follow-up on September 25 narrowed the root cause In preliminary findings from the security team published by Chen on her X account, the intruder penetrated the core backend system of the exchange's wallet service, forged transfer information, and triggered the approval signing procedure to push funds to external addresses — instructions that resembled the platform's normal transfer order types.
Critically, no evidence indicates that the wallet's private keys were compromised. Chen stated that a key leak has been ruled out, "which means a more severe risk scenario has been eliminated," and that containment is complete, with no further possibility of unauthorized funds leaving the platform. According to the company's own assessment, Bitget's three-tier wallet architecture kept its cold wallets entirely unaffected.
How exactly the attacker penetrated the backend remains under investigation. Bitget said it will publish a full technical report as soon as the intrusion method is identified. The emergency response team acted immediately after the incident, identified and reported the addresses that received the abnormal funds, and notified law enforcement agencies and on-chain security firms working the case.
A backend intrusion of this kind is harder to catch than a leaked key, because the attacker operates inside infrastructure the exchange itself trusts. Withdrawals remain suspended while multiple technical teams run system recovery and security hardening in parallel. Chen declined to commit to a restart timeline, saying Bitget would announce a date the moment one is confirmed and would not "hastily promise a schedule it cannot keep."
Freeze on Stolen Funds Puts Resumption in Focus
A concrete freeze has landed on part of the stolen funds. Circle blacklisted an address labeled "Bitget Exploiter 8" on Etherscan at 05:00 UTC on Friday, and blockchain security firm MistTrack reported that Tether subsequently banned the wallet as well. The action locks up roughly $318,000 in stablecoins — about 218,023 USDT and 99,990 USDC, held alongside 170.47 ETH as of 15:10 UTC — only a small fraction of the $351.6 million haul.
The limitation is structural: MistTrack's tracker shows other exploiter addresses still holding more than 63,000 ETH, an asset no issuer can freeze. Circle's rapid response marks a contrast with April's $285 million Drift hack, when roughly $232 million in USDC crossed from Solana to Ethereum before any blacklisting, drawing criticism from on-chain sleuths including ZachXBT.
Read together, the two disclosures frame the breach as an operational-security failure rather than a cryptographic one: the private keys stayed intact, yet the signing pipeline itself could be manipulated from inside the backend. On-chain tracing of the roughly $351.6 million in drained funds — verifiable transaction by transaction — will determine how much can be frozen or clawed back before the attackers finish bridging the proceeds.
The official post-mortem to date attributes the loss to the backend intrusion, with remediation details still pending. Coverage pools such as Bitget's $464 million fund — now standard across venues from Bitget to Coinbase Global (COIN) — have become a survival requirement for exchanges. The next catalysts to watch: the withdrawal-resumption notice and the full technical report.