Full Breakdown
Bitget Exchange Suffers $351.6 Million Hack, Suspects North Korean Actors
By Drooid · · How we work
Incident Overview
On September 24, 2026 Bitget’s monitoring systems flagged unauthorized transfers from its hot and warm wallets at approximately 18:31 UTC. Cold-wallet stores remained untouched, and the exchange immediately suspended withdrawals while keeping deposits and trading active.
Technical Method and Asset Impact
Investigators say attackers breached a backend component that prepares transaction data and spoofed that data to trigger Bitget’s normal authorization-signing process. By manipulating the intermediary system rather than stealing private keys, the perpetrators moved funds without cryptographic control of the wallets. Stolen assets included ETH, XRP, BNB, AVAX, USDT, USDC and other tokens, with on-chain trackers estimating the total loss at $351.6 million.
Attribution to North Korean Hackers
Preliminary forensic work identified IP addresses linked to VPN services previously used by a known North Korean hacking group. The intrusion pattern mirrors earlier operations attributed to the DPRK, including the February 2025 $1.5 billion Bybit hack tied to the Lazarus Group’s TraderTraitor cluster. On-chain researcher Specter also traced stolen XRP to an address previously associated with a North Korean-linked exploit.
Financial Safeguards and Market Reaction
Bitget’s User Protection Fund holds more than $464 million, exceeding the reported loss, and the exchange asserts that customer balances remain fully covered. Market data showed a short-term dip in Bitget’s native BGB token, while Bitcoin and Ether experienced modest declines.
Official Statements & Responses
CEO Gracy Chen emphasized that private keys were not compromised and that the breach was contained, preventing further outflows. She indicated withdrawals could resume within hours or days, though no firm timetable was set, and noted that some stolen funds had already been recovered, without disclosing amounts. The exchange has reported the incident to law-enforcement agencies and is cooperating with global investigators and blockchain security firms.
Conflicting Reports & Gaps
Initial on-chain monitoring estimated the outflow at roughly $183 million, a figure later revised by Bitget to $351.6 million after broader blockchain analysis. The exact method of initial access to the backend system remains undetermined, and a full forensic report has not yet been published.
Verbatim Quotes
- “We’ve identified some IP addresses that match the VPN choices by a certain DPRK group,” — Gracy Chen, Bitget CEO
- “The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” — Gracy Chen, Bitget CEO
What’s Next
Bitget will publish a comprehensive incident report after completing its technical review and will announce a specific withdrawal-restoration window once confirmed. Ongoing collaboration with law-enforcement and blockchain foundations aims to trace and potentially freeze additional stolen assets.
