NewsCryptoBitget Attributes $351.6 Million Exchange Hack to Backend Breach, Cites Possible North Korean Link

Bitget Attributes $351.6 Million Exchange Hack to Backend Breach, Cites Possible North Korean Link

Author: TechNext24·

Key Takeaways

  • •The attackers compromised a backend system in Bitget's wallet infrastructure and used it to spoof transaction data, triggering the exchange's own authorization process rather than stealing private keys or forging user withdrawals.
  • •Bitget suspended withdrawals detecting approximately $351.6 million in unauthorized transfers from hot wallets on September 24, while deposits and trading remained operational and cold wallets stayed secure.
  • •Chief Executive Gracy Chen said preliminary findings show similarities to North Korean-linked hacking groups based on VPN usage patterns, but the attribution has not been independently confirmed and investigations with law enforcement and on-chain security firms are ongoing.
  • •Customer account balances remain accurate and the estimated loss is covered by Bitget's User Protection Fund, which currently holds more than $464 million.
  • •Bitget has flagged the addresses involved and pledged to publish a full incident report, but has not set a date for resuming withdrawals pending completion of its security review.
Bitget Attributes $351.6 Million Exchange Hack to Backend Breach, Cites Possible North Korean Link

Cryptocurrency exchange Bitget says the attackers who moved roughly $351.6 million from the platform on Thursday did not steal private keys or forge user withdrawal requests. Instead, the company said, the intruder compromised a critical backend system in its wallet infrastructure, used it to spoof transaction data, and triggered Bitget's own authorization process to move the funds. The distinction matters because private keys are typically an exchange's most closely guarded asset, while the backend systems that route and verify transactions represent a wider operational attack surface.

Gracy Chen, the exchange's chief executive, disclosed the breach at 19:31 WAT on September 24, saying Bitget had detected unauthorized transfers from some of its hot wallets. The company subsequently suspended withdrawals, while deposits and trading remained operational. Chen addressed the incident in a series of posts on X (1, 2, 3).

In a follow-up explanation on Friday, Chen said the attacker had compromised a backend system rather than obtaining the private keys that control Bitget's wallets. “Private key compromise has been ruled out,” Chen said, according to reports of her statement.

The exact method used to gain access to the backend system remains under investigation. Bitget said it plans to publish a full incident report covering the root cause and the corrective measures it intends to adopt.

Preliminary findings point to North Korean hackers

Chen said preliminary findings had identified similarities between the attack and previous operations linked to North Korean hacking groups. According to Chen, investigators found IP addresses whose VPN usage matched choices associated with a North Korean group, and she said the overall pattern of the attack appeared similar to prior operations attributed to North Korean hackers.

The claim has not been independently confirmed, and Bitget has not identified the attackers. The exchange said investigations involving law enforcement agencies and on-chain security firms are ongoing.

North Korean-linked hackers have previously been associated with major cryptocurrency thefts. The FBI attributed the February 2025 theft of about $1.5 billion from the crypto exchange Bybit to North Korea. That theft is widely described as the largest single cryptocurrency theft on record; the Bitget loss, at roughly $351.6 million, is less than a quarter as large. United Nations investigators have previously reported that stolen cryptocurrency has helped fund North Korea's weapons programmes.

Cold wallets unaffected

Bitget said the incident was limited to portions of its hot and warm-wallet infrastructure, while its cold wallets remained secure. Hot wallets are connected to the internet and are commonly used to facilitate transactions, while cold wallets are kept offline to reduce exposure to online attacks.

The exchange said customer account balances remain accurate and that the estimated loss is covered by its User Protection Fund, a reserve maintained for losses of this kind, which currently holds more than $464 million.

Bitget has flagged addresses associated with the transfers and said it has contacted law enforcement agencies and on-chain security firms as part of efforts to investigate and recover the assets.

The company has not given a date for when withdrawals will resume. It said restoration would take place once its security review is completed and that updates would be provided through its official channels. The resumption of withdrawals, the promised incident report and the effort to trace the flagged funds are the key developments to follow as the investigation proceeds.

Bitget's footprint in Nigeria

The incident comes as Bitget has built a significant presence among cryptocurrency users in Nigeria. Bitget Wallet, the exchange's separate self-custody wallet product, was previously ranked No. 1 in both the overall and finance categories of Apple's App Store in Nigeria, and the company said its Nigerian Wallet user base grew by more than 233% in June 2024.

However, the company said the Wallet product operates separately from the exchange infrastructure affected by Thursday's incident. The breach affects funds held in the exchange's hot and warm wallets, while the separate Wallet was not affected, according to Chen. The separation underscores the difference between assets held on an exchange, which depend on the platform's own security, and those managed directly by users through a self-custody product.

Bitget detected the unauthorized transfers at 19:31 WAT on September 24 and said its emergency response team was activated within minutes. The exchange has promised further updates as its investigation continues.