NewsCryptoBitget Probes Possible North Korea Link in $351.6 Million Breach; Withdrawals Remain Paused

Bitget Probes Possible North Korea Link in $351.6 Million Breach; Withdrawals Remain Paused

Author: Coindoo·

Key Takeaways

  • •Bitget estimates the breach affected $351.6 million in assets, an internal figure far higher than the roughly $170 million in transfers initially observed on-chain.
  • •The exchange says a private-key leak has been ruled out, with the attacker instead compromising a critical backend system and using it to spoof transaction data accepted by the authorization process.
  • •Withdrawals are suspended while remediation and security hardening continue, but deposits and trading remain available and customer balances are reported accurate.
  • •Cold wallets were unaffected, and Bitget says the loss is covered by its User Protection Fund, which holds more than $464 million.
  • •CEO Gracy Chen said some attack-related IP addresses matched VPN-use patterns tied to a North Korean hacker organization, though the company stresses this attribution remains preliminary.
Bitget Probes Possible North Korea Link in $351.6 Million Breach; Withdrawals Remain Paused

Crypto exchange Bitget has confirmed that transfers from wallets linked to the platform were unauthorized, escalating a security incident that first surfaced as suspicious on-chain movements. The company estimates the affected assets at $351.6 million, says a private-key leak has been ruled out, and has suspended withdrawals while it completes remediation and security hardening. Investigators are examining whether the attack traces back to a North Korean hacker organization, though that assessment remains preliminary.

How the Bitget Story Changed Overnight

Coindoo first covered the unusual wallet movements in an earlier report, when funds from Bitget-linked wallets were observed moving to a fresh address and being swapped on-chain. Bitget has since confirmed that the transfers were unauthorized.

The two dollar figures should not be read as competing estimates of the same thing. The $170 million number came from the initial visible on-chain flow. Bitget's later $351.6 million figure is the exchange's internal estimate of the assets affected by the breach.

Bitget has not published a wallet-by-wallet reconciliation explaining the difference. What is clear is that the first alert captured only part of a wider incident that the exchange later confirmed from inside its own systems.

The North Korea Clue Is Not a Final Attribution

During a live security update, Bitget CEO Gracy Chen said some IP addresses associated with the attack matched VPN-use patterns linked to a North Korean hacker organization. She also said the activity resembled previous attacks associated with North Korean operators, according to ChainCatcher's report.

That is a preliminary lead, not a completed attribution. Blockchain analytics firms and United Nations reporting have tied North Korea-linked hacking groups to some of the largest cryptocurrency thefts on record, including exchange breaches and cross-chain bridge exploits totaling billions of dollars. Confirmed attributions in past cases have typically followed months of forensic work. Bitget has not named a group or released the forensic evidence behind the assessment. The company's current position is that North Korean involvement cannot be ruled out while investigators continue to trace the intrusion.

The Attack Did Not Require a Stolen Private Key

Bitget's explanation changes the technical question around the breach. In a September 25 update, Chen said the attacker compromised a critical backend system within the exchange's wallet infrastructure. Bitget says that system was then used to create spoofed transfer data that reached its authorization process and moved funds out.

Here is what we can confirm at this stage:

On the attack: Our security team has made initial progress in tracing the source. The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization…

— Gracy Chen @Bitget (@GracyBitget) September 25, 2026

The exchange says a private-key leak has been ruled out. It also says it has contained the incident and that no further unauthorized transfers are possible.

That does not make the breach less serious. It shifts the focus from key custody to the systems surrounding it. The distinction matters industry-wide: defenses such as cold storage and multi-signature arrangements are built to stop key theft, not to validate the transaction data an internal system feeds into an approval workflow. If Bitget's account is confirmed, the attacker did not need to possess a wallet key; they needed access to infrastructure capable of producing transfer information that the approval process accepted.

The full incident report therefore matters more than the early North Korea clue. It will need to explain how manipulated data entered the authorization flow, which controls failed to stop it, and what has changed before withdrawals resume.

A Protection Fund Can Cover Losses, Not Restore Access

Bitget says its cold wallets were not affected and that the $351.6 million loss falls within the coverage of its User Protection Fund, which it says holds more than $464 million. The exchange also says customer account balances remain accurate. Reserve funds of this kind have become a standard backstop among major exchanges, with Binance's SAFU and OKX's protection fund operating on similar principles.

This is the practical distinction for users. The protection fund addresses whether Bitget can absorb the financial loss. It does not, by itself, restore confidence that the wallet systems are ready for normal withdrawals.

Deposits and trading remain available, according to Bitget's official security notice. Withdrawals remain suspended while the exchange works on remediation and security hardening. Chen said Bitget would announce a restart schedule only once it can give a confirmed timeframe.

The Remaining Question Is Inside Bitget's Systems

The initial $170 million alert raised the question of whether the suspicious wallet movements were real. Bitget has now answered that part: it says the transfers were unauthorized and the total exposure was far higher.

The harder question remains. If private keys were not stolen, how did a compromised backend system generate transfer data that Bitget's authorization process accepted?

That answer—not another revised loss estimate—will show whether the exchange has addressed the weakness that allowed the breach in the first place.

This article is provided for informational purposes only and does not constitute financial or investment advice. Attribution and technical findings may change as Bitget and independent investigators release further evidence.