NewsCryptoBitget Hack Losses Climb to $387.5 Million as Exchange Points to North Korea

Bitget Hack Losses Climb to $387.5 Million as Exchange Points to North Korea

Author: Decrypt·

Key Takeaways

  • •Attackers breached a backend system in Bitget's wallet infrastructure and spoofed transaction data to trick the exchange's authorization process, without obtaining private keys or forging user withdrawal requests.
  • •Estimated losses climbed from roughly $183 million within an hour of detection to $387.5 million, with about 103 million XRP valued near $157 million as the largest single component of the haul.
  • •Bitget says the unauthorized outflow has been stopped and its User Protection Fund, which holds more than $464 million, will cover the full loss so that customer account balances remain intact.
  • •CEO Gracy Chen said identified IP addresses and on-chain patterns match techniques previously used by North Korea's state-linked hacking groups, though the attribution remains unconfirmed and law enforcement is investigating.
  • •Bitget is conducting an ongoing investigation with security firms Mandiant and SlowMist, and has paused withdrawals until it announces a user plan, with a full incident report and root-cause analysis promised after remediation is complete.
Bitget Hack Losses Climb to $387.5 Million as Exchange Points to North Korea

Crypto exchange Bitget has confirmed that hackers stole roughly $387.5 million in digital assets in a breach detected on September 24—believed to be the largest crypto theft of the year. The attackers did not take private keys. Instead, they spoofed transaction data to trick the exchange's own authorization systems into approving transfers that looked routine, drawing funds from hot and warm wallets. The haul includes roughly 103 million XRP worth about $157 million. Chief Executive Gracy Chen has said that IP addresses and on-chain patterns match techniques previously used by North Korea's state-linked hackers, though the attribution remains unconfirmed, and Bitget says law enforcement is now investigating.

A rising tally

Bitget's security systems detected unauthorized transfers leaving some of its hot wallets at 18:31 UTC on September 24. Within about an hour, on-chain investigators had already tallied roughly $183 million in stablecoins, Ethereum, and other crypto assets sliding out of wallets tagged as belonging to the exchange. By the time Bitget went hours later to confirm the hack, total losses had grown to $351.6 million. The company, one of the largest exchanges in the industry, raised that figure to $387.5 million today in a statement posted on X.

Chen explained what happened in a livestream and a series of posts on X. "They did not forge user withdrawal requests, nor did they obtain our private keys of the cold wallet and any hot, warm wallet," she said.

Instead, the attackers broke into a backend system inside Bitget's wallet infrastructure and used it to spoof transaction data, fooling the exchange's own authorization process into approving payouts that appeared routine. Put simply, nobody stole the vault combination. Someone forged paperwork convincing enough that the system signed off without asking questions—the digital equivalent of slipping a fake withdrawal slip past a bank teller who checks the form, not the person.

That distinction matters because private-key custody was not the only security control involved: the systems that interpret transaction data and authorize transfers were also part of the path to the loss. Bitget's eventual root-cause analysis should show how those controls were bypassed and what remediation the exchange applies.

On-chain detectives moved first

Blockchain sleuths had pieces of the story before Bitget confirmed anything. Pseudonymous researcher DCF GOD flagged a freshly created wallet that spent $19.67 million in USDT0—a cross-chain version of the dollar-pegged stablecoin Tether—to buy 7,111 ETH in six minutes, paying roughly 5% above market price through the decentralized exchanges UniswapX and 1inch Fusion.

More wallets tagged as Bitget's followed, sending assets across at least five blockchains to addresses controlled by the attacker. The single biggest piece of the haul turned out to be roughly 103 million XRP, worth about $157 million.

Bitget's investigation, conducted alongside security firms Mandiant and SlowMist, remains ongoing, Chen said in a post on X:

Within 24 hours of the September 24 (UTC) incident: here is our further update as promised. Our investigation with Mandiant and SlowMist is ongoing — thorough forensic analysis takes more than 24 hours, and further findings will be shared as they become available. Three key…

— Gracy Chen @Bitget (@GracyBitget) September 25, 2026

Customer balances stay intact

Chen said the outflow has since been stopped and that no further unauthorized transfers are possible. Bitget's User Protection Fund, which holds more than $464 million, will cover the full loss, she said, meaning customer account balances remain intact even though the stolen funds themselves are gone.

Deposits and trading kept running throughout the incident; withdrawals alone were frozen as a precaution. Bitget built the protection fund years ago for precisely this kind of scenario, given how common hacks unfortunately are across the industry. Back in 2023, the fund stood at $300 million, set aside specifically to cover hacks and theft so that users would not be left holding the loss.

North Korea is the usual suspect

As to who was behind the attack, Chen has pointed a finger at Pyongyang, though carefully. "We've identified some IP addresses that match the VPN choices by a certain DPRK group," she said, adding that "the pattern looks very much like what the North Korean team did before."

She has also said the on-chain signatures line up with techniques tied to North Korean state-linked hacking groups, while stressing that the attacker's identity has not been confirmed and that no technical evidence has been made public. Chen added that she has personally been targeted by the same group before, losing about $80,000 from a personal wallet outside Bitget.

North Korea's Lazarus Group, also tracked under the codename TraderTraitor, has been blamed for the industry's biggest heists, including the $1.4 billion hack of rival exchange Bybit in February 2025, which the FBI confirmed weeks later was North Korean work. Blockchain analytics firm Chainalysis puts the country's 2025 haul at more than $2 billion.

Bitget has pledged a full incident report, including root-cause analysis, once its technical teams finish system remediation. Withdrawals remain paused until tomorrow, when the exchange will announce a plan for users interested in withdrawing their funds.