NewsCryptoBitget Confirms $351.6 Million Hot Wallet Breach, Points to North Korea-Linked Hackers

Bitget Confirms $351.6 Million Hot Wallet Breach, Points to North Korea-Linked Hackers

Author: Metaverse Post·

Key Takeaways

  • •The breach affected roughly $351.6 million across multiple chains, with the largest single loss being about 102.9 million XRP valued near $157.5 million on the XRP Ledger.
  • •Attackers compromised a critical backend wallet-service system and forged transfer details to trigger the authorized signing process, and Bitget explicitly ruled out private key leakage.
  • •Bitget's three-tier wallet architecture limited the incident to portions of the hot and warm wallet layers, with all cold wallets confirmed secure, and withdrawals were suspended while deposits and trading stayed operational.
  • •CEO Gracy Chen said the User Protection Fund, holding over $464 million, is sufficient to cover user losses, rejected FTX comparisons, and confirmed Bitget Wallet runs on separate infrastructure and was unaffected.
  • •Attribution evidence points toward North Korea-linked actors, and analyst Specter linked the bridged stolen XRP to the July $24 million AFX hack attributed to the Lazarus Group sub-actor TraderTraitor.
Bitget Confirms $351.6 Million Hot Wallet Breach, Points to North Korea-Linked Hackers

Cryptocurrency exchange Bitget confirmed on September 24, 2026, that its security systems detected unauthorized transfers from a limited number of hot wallets at 18:31 UTC. The exchange said approximately $351.6 million in assets were affected, making the incident one of the largest exchange security breaches since Bybit's $1.5 billion loss.

Initial on-chain monitoring had suggested that three hot wallets and one cold wallet were compromised, with more than $170 million moved and swapped into ETH. Bitget later clarified that its three-tier wallet architecture contained the breach to portions of the hot and warm wallet layers, while all cold wallets across every chain were confirmed secure and unaffected. Hot wallets stay online to process day-to-day withdrawals, while cold storage is kept offline; isolating the bulk of an exchange's assets in the latter is the standard buffer that limits how much capital is exposed when an online signing layer is compromised.

The stolen assets span multiple chains, including Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. The largest single loss occurred on the XRP chain, where roughly 102.9 million XRP valued at about $157.5 million was taken. Other affected assets included approximately 31,890 ETH, 34.75 million USDT, 21 million USDC, 19.67 million USD₮0, 3,000 XAUt, 12,719 BNB, 821,012 AVAX, and 20.6 million TRX. On-chain investigators reported that the attacker swapped most of the EVM-chain proceeds into nearly 68,000 ETH.

According to Bitget's security team, the hackers breached a critical backend system of the wallet service, forged transfer details, and invoked the authorized signing process to move funds out, explicitly ruling out private key leakage — an attack path that targets the exchange's internal authorization workflow rather than the cryptographic keys themselves. As a precaution, withdrawals were suspended while deposits and trading remained operational.

The exchange flagged the abnormal addresses, engaged law enforcement and on-chain security firms, and said several blockchain foundations have already frozen attacker wallets. Bitget committed to hourly updates and a full incident report with root-cause analysis within 24 hours.

News of the incident first emerged in a post on X from 谢家印 (Xie Jiayin):

今天凌晨2:31 Bitget安全系统监测到部分热钱包出现异常转账。安全团队在第一时间启动应急响应机制。 一、已确认的情况: 1、初步评估涉及金额约3.516亿美金 2、冷钱包及平台绝大部分资产完整,未受影响…

— 谢家 (@xiejiayinBitget) September 24, 2026

Financial Backing and Attribution Concerns

Bitget emphasized that user funds are fully protected, noting the loss falls within its User Protection Fund, which holds more than $464 million in publicly verifiable wallets, and that the exchange additionally maintains over $1 billion in proprietary capital. CEO Gracy Chen stated that the fund alone is sufficient to cover the losses and pushed back against comparisons to FTX, arguing the platform is capable of withstanding a potential withdrawal run. She also confirmed that Bitget Wallet operates on entirely separate infrastructure and was not affected.

Chen summarized her remarks on X:

刚才上午跟大家做了个三个多小时的直播,这里总结一下直播中聊到的点: ① Bitget 安全事件12小时进展通报。以下为具体信息,不打官腔。 ②…

— Gracy Chen @Bitget (@GracyBitget) September 25, 2026

Regarding attribution, Chen said the attacker's identity cannot be confirmed with complete certainty, but that the evidence points toward North Korea-linked actors. Certain IP addresses involved in the breach closely match VPN patterns used by a DPRK-associated group, and the attack methodology is consistent with their known techniques. The scale of the loss fits a wider pattern: North Korea-linked hacking units have been blamed by investigators for some of the sector's largest exchange thefts, including Bybit's $1.5 billion loss, with proceeds typically moved and swapped across chains to frustrate recovery. Independent analyst Specter linked the stolen XRP, which was bridged, to the $24 million AFX hack from July that was attributed to the Lazarus Group sub-actor TraderTraitor, the designation U.S. agencies and industry researchers have used for a cryptocurrency-focused wing of Lazarus operations. Bitget has notified relevant authorities and is cooperating with investigations globally.

Regarding who is behind the hack: I present to you THE LAZARUS GROUP. just linked this hack to the AFX hack, which stole $24M in July and was specifically attributed to TraderTraitor. The stolen XRP from Bitget was bridged and can be directly linked to the funds stolen in the… pic.twitter.com/cRPdhhdpjQ

— Specter (@SpecterAnalyst) September 25, 2026

The restoration of withdrawals remains pending, with Chen stating that no precise timeline will be committed to until system security is fully confirmed, as remediation across the many affected cryptocurrencies and networks is still underway. Near-term markers for readers include the promised root-cause report, the resumption of withdrawals, and any further freezes or on-chain movement involving the flagged attacker addresses.

This article was originally published by Metaverse Post.