NewsCryptoBitget Confirms $351.6 Million Hack Across Hot and Warm Wallets, Suspects North Korean Group

Bitget Confirms $351.6 Million Hack Across Hot and Warm Wallets, Suspects North Korean Group

Author: Crypto Valley Journal·

Key Takeaways

  • •Bitget confirmed a hack that drained USD 351.6 million from parts of its internet-connected hot and warm wallets, with losses spread across seven blockchains and the largest single-chain loss on the XRP Ledger.
  • •The attacker manipulated a backend system to forge transfer data that passed Bitget's standard authorization process, and the exchange has ruled out the theft of private keys.
  • •Bitget suspects a North Korean hacker group based on IP addresses and attack-pattern parallels to earlier incidents, but the attribution remains unconfirmed by any government agency or security firm.
  • •Withdrawals have been suspended without a fixed restart date, while deposits and trading continue, and Bitget's User Protection Fund of more than USD 464 million is reported to cover the full loss.
  • •Some affected chain foundations have frozen attacker addresses, and a wallet linked to the theft swapped roughly USD 19.67 million in USDT0 for 7,111 ETH at a premium of about 5% to reduce the risk of a freeze.
Bitget Confirms $351.6 Million Hack Across Hot and Warm Wallets, Suspects North Korean Group

Crypto exchange Bitget has confirmed a USD 351.6 million hack that affected parts of its hot and warm wallets. The company suspects a North Korean hacker group behind the attack and has suspended withdrawals until further notice.

What Happened

Bitget is a crypto exchange where customers deposit funds, trade with them, and withdraw assets to their own addresses. The platform spreads its holdings across three tiers: always-connected hot wallets handle daily operations, warm wallets serve as a buffer, and cold wallets have no internet connection. As a result, the closer a tier sits to day-to-day business, the larger its attack surface.

At 18:31 UTC on September 24, 2026, Bitget's security systems flagged unauthorized outflows from the two connected tiers. A few hours later, CEO Gracy Chen confirmed the incident in a post on X. On-chain analysts initially estimated the outflow at USD 180 million, but the confirmed total came in at roughly twice that figure. The losses span seven chains: Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Smart Chain, and Base.

Backend Manipulation Instead of Stolen Keys

Chen initially declined to speculate on the attack vector before the investigation was complete, but the sequence of events is now becoming clearer. The attacker gained access to a critical backend system in the wallet infrastructure. There, the attacker forged transfer data and thus got Bitget's regular authorization process to approve the outflows. The exchange rules out the theft of private keys.

This distinction is key to assessing the case. With a stolen key, an attacker can sign transfers directly. In Bitget's case, however, signing stayed with the exchange, and the approval therefore went through the usual controls — only the data behind it came from the attacker. Consequently, even well-secured key custody offers no protection when the upstream system supplies false transfer data. For institutional clients in particular, reviewing internal approval processes now carries more weight.

Scope of the Losses

According to the exchange, Bitget's cold wallets remain untouched and secure, and the attack hit only part of the hot and warm tier. Affected assets include ETH, XRP, USDT, USDC, AVAX, and BNB. An exchange that supports many chains must keep connected holdings on each of them for withdrawals, which increases the number of attack points. Bitget reported its largest single-chain loss on the XRP Ledger. In addition, the issuers of the stablecoins USDT and USDC can freeze affected balances.

From USD 170 Million to USD 351.6 Million

The first reports spoke of more than USD 170 million flowing from Bitget wallets to an unidentified address. These early on-chain analyses covered only some of the affected chains at first; the full cross-chain analysis finally produced the USD 351.6 million figure that Chen confirmed. There is consequently no contradiction between the two numbers.

At the same time, the attacker tried to shield the loot from a freeze. A newly created wallet with the address prefix "0xe410" swapped roughly USD 19.67 million in USDT0 — a cross-chain variant of Tether's USDT — for 7,111 ETH. The trade took only a few minutes, and the wallet accepted a premium of about 5% above the market price — just under USD 1 million. Speed apparently outweighed price: unlike stablecoins, an ETH balance cannot be frozen after the fact.

Still, the plan did not fully work. In its twelve-hour interim report, the exchange said some affected chain foundations had frozen the attacker's addresses. Chain foundations are the organizations behind individual networks, and some of them can block addresses on their chain. Bitget does not name the chains or the amounts at stake, so nobody can say how much of the USD 351.6 million actually remains stuck.

Withdrawal Freeze and the Reserves Behind It

For customers, the withdrawal freeze in place since the incident weighs heaviest for now. Deposits and trading, by contrast, continue as normal. Bitget has not given a fixed date for resuming withdrawals; the company only wants to communicate deadlines once it can guarantee them. Customers can therefore trade their balances on the platform but cannot move them to their own wallet or another exchange.

Financially, the exchange considers itself covered. Bitget's User Protection Fund is a reserve for customer losses. According to the company, it holds more than USD 464 million and covers the entire loss — on paper, the fund alone exceeds the loss by more than USD 110 million. Moreover, Bitget puts its own assets at over USD 1 billion. The fund's coverage does not by itself restore access to customers' balances, however — that still depends on when withdrawals resume, and no date has been set.

"Bitget has been through multiple market cycles. We will not walk away from this. We will account for every dollar and every decision with full transparency," said Gracy Chen, CEO of Bitget.

A full incident report with a root cause analysis should bring more clarity. Bitget has committed to publishing it no later than 24 hours after its first security notice, and only this report is expected to explain how the attacker gained access to the backend system in the first place. The details of the sequence so far come from Chen's posts on X and the twelve-hour interim report.

Parallels to Bybit and Ronin

Bitget bases its suspicion of North Korea on two indicators. Investigators identified IP addresses linked to VPN services that North Korean hackers had used before. In addition, the attack pattern resembles earlier operations with ties to North Korea. Nevertheless, this remains a preliminary assessment by the company; neither a government agency nor an on-chain security firm has confirmed the attribution so far.

By comparison, the Bybit hack of February 2025 is solidly documented. Roughly USD 1.5 billion flowed out in that attack, more than four times the Bitget loss. The FBI and its reporting center IC3 attributed the Bybit hack to North Korea, and both track the activity under the name "TraderTraitor." Earlier US advisories and security researchers link this label to the Lazarus Group. The entry point was a supply chain attack on the multisig platform Safe{Wallet}: using manipulated software, the attackers got the legitimate signers to approve the outflow, which comes closest to the Bitget case. Bitget had supported Bybit at the time, and now Bybit CEO Ben Zhou has offered help in return. Zhou is also updating the LazarBounty platform to trace the funds from the Bitget hack.

Ronin offers another precedent for North Korean attribution: in March 2022, attackers drained roughly USD 625 million from the Ronin Bridge, which connects the game Axie Infinity to Ethereum, and the US Treasury attributed that theft to the Lazarus Group as well.

This article is based on reporting from Crypto Valley Journal.