Bitget Suspects North Korean Hackers Behind $352 Million Crypto Breach

date
23:02 25/09/2026
avatar
GMT Eight
Crypto exchange Bitget is investigating a security breach that resulted in approximately $351.6 million in unauthorized digital-asset transfers, with preliminary evidence pointing to possible involvement by North Korean hackers. The attack affected parts of the exchange’s hot and warm wallet infrastructure across several blockchains, while cold wallets remained secure. Bitget says the breach has been contained, customer balances remain accurate and losses are fully covered by its $464 million-plus User Protection Fund.

Bitget detected unauthorized transfers from some of its wallets on Thursday afternoon in the U.S., according to CEO Gracy Chen. The incident involved 19 transfers from hot and warm wallets and affected assets including ether, XRP, USDT, USDC, Avalanche and BNB. Transactions occurred across networks including Ethereum, XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum.

Initial on-chain estimates placed the losses at around $183 million, but Bitget later said those calculations did not capture activity across all affected blockchains. The exchange now estimates approximately $351.6 million in digital assets were involved. Cold wallets, which typically store assets offline for greater security, were not affected.

Bitget’s preliminary investigation has raised suspicions of North Korean involvement. Chen said investigators identified IP addresses associated with VPN services previously used by a North Korean hacking group, while aspects of the attack resembled patterns seen in earlier operations attributed to the country. However, the specific method used to gain access to Bitget’s systems remains under investigation, and the attribution has not been confirmed.

According to Bitget, the attacker compromised a critical backend wallet system and used it to spoof transfer information before triggering the exchange’s authorization-signing process. Chen said investigators had ruled out a compromise of private keys. The vulnerability has since been contained, preventing additional unauthorized transfers.

Withdrawals remain temporarily suspended as Bitget repairs and strengthens the affected infrastructure, while deposits and trading are continuing normally. Chen did not provide a firm timeline for restoring withdrawals but said the disruption could last hours or days rather than weeks.

Bitget said customer account balances remain accurate despite the scale of the breach. The company also maintains that the entire loss can be covered by its User Protection Fund, which holds more than $464 million. That would allow the exchange to absorb the financial impact without passing losses on to customers.

Other crypto companies are also assisting with the response. Bybit CEO Ben Zhou said his company was prepared to support Bitget after Bitget provided assistance following Bybit’s $1.5 billion hack in February 2025. Bybit is also updating its LazarusBounty platform to help trace the stolen assets as Bitget continues investigating both the attack and the suspected North Korean connection.