Close Menu
Crypto Valley Journal
    Facebook X (Twitter) Instagram
    Crypto Valley Journal
    • Hot Topics
      • News
      • Minds
    • Focus
      • Background
      • Blockchain
      • Legal & Compliance
      • Non-Fungible Token (NFTs)
    • Investing
      • Markets
      • Financial Products
      • Decentralized Finance (DeFi)
      • Exchange overview
    • Education
      • Basics
      • Glossary
      • Politicians on crypto
    • Statistics
      • Bitcoin-ETF-Flows
      • Ethereum-ETF-Flows
      • Crypto market data
      • On-chain data
    • Academy
      • Overview
      • Part 1: Blockchain
      • Part 2: Money
      • Part 3: Bitcoin
      • Part 4: Cryptocurrencies
      • Part 5: Decentralized Finance
      • Part 6: Investing
    • English
      • Deutsch
    Crypto Valley Journal
    You are at:Home » Hot Topics » News » Crypto exchange Bitget loses USD 351.6 million in a hack
    The Bitget hack drained USD 351.6 million from hot and warm wallets; the exchange suspects North Korea and has halted withdrawals.

    Crypto exchange Bitget loses USD 351.6 million in a hack

    By Editorial Office CVJ.CH on 25. September 2026 News

    Crypto exchange Bitget has confirmed a USD 351.6 million hack that hit parts of its hot and warm wallets. The company suspects a North Korean hacker group behind the attack and has suspended withdrawals until further notice.

    Bitget is a centralized crypto exchange where customers deposit funds, trade with them and withdraw assets to their own addresses. The platform spreads its holdings across three tiers. Always-connected hot wallets handle daily operations, warm wallets serve as a buffer and cold wallets have no internet connection. As a result, the closer a tier sits to day-to-day business, the larger its attack surface. At 18:31 UTC on 24.09.2026, Bitget's security systems flagged unauthorized outflows from the two connected tiers. A few hours later, CEO Gracy Chen confirmed the incident on X. On-chain analysts initially estimated the outflow at USD 180 million. However, the confirmed total came in at roughly twice that figure. The losses span seven chains: Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Smart Chain and Base.

    Subscribe to our newsletter

    The best articles of the week, directly delivered into your mailbox.

    Bitget hack: backend manipulation instead of stolen keys

    Initially, Chen declined to speculate on the attack vector before the investigation was complete. The sequence of events is now becoming clearer. The attacker gained access to a critical backend system in the wallet infrastructure. There, the attacker forged transfer data and thus got Bitget's regular authorization process to approve the outflows. The exchange rules out theft of private keys.

    This distinction is key to assessing the case. With a stolen key, an attacker can sign transfers directly. In Bitget's case, however, signing stayed with the exchange. The approval therefore went through the usual controls. Only the data behind it came from the attacker. Consequently, even well-secured key custody offers no protection when the upstream system supplies false transfer data. Not least for institutional clients, reviewing internal approval processes now carries more weight.

    According to the exchange, Bitget's cold wallets remain untouched and secure. The attack hit only part of the hot and warm tier. Affected assets include ETH, XRP, USDT, USDC, AVAX and BNB. An exchange that supports many chains must keep connected holdings on each of them for withdrawals. This increases the number of attack points. Bitget reported its largest loss on a single chain on the XRP Ledger. In addition, the issuers of the stablecoins USDT and USDC can freeze affected balances.

    From USD 170 million to USD 351.6 million

    The first reports spoke of more than USD 170 million flowing from Bitget wallets to an unidentified address. These early on-chain analyses covered only some of the affected chains at first. The cross-chain analysis finally produced the USD 351.6 million figure that Chen confirmed. Consequently, there is no contradiction between the two numbers.

    At the same time, the attacker tried to shield the loot from a freeze. A newly created wallet with the address prefix "0xe410" swapped roughly USD 19.67 million in USDT0 for 7,111 ETH. The trade took only a few minutes. To do so, the wallet accepted a premium of about 5% above the market price. That works out to just under USD 1 million. Speed apparently outweighed price. After all, unlike with stablecoins, nobody can freeze an ETH balance after the fact.

    Still, the plan did not fully work. In its twelve-hour interim report, the exchange said some affected chain foundations had frozen the attacker's addresses. Chain foundations are the organizations behind individual networks, and some of them can block addresses on their chain. Yet Bitget does not name the chains or the amounts at stake. As a result, nobody can say how much of the USD 351.6 million actually remains stuck.

    Ray Dalio advises 10 to 15% gold and a small Bitcoin position, because he expects a US debt crisis within about three years. Minds

    Star investor Ray Dalio considers Bitcoin inferior to gold

    The Trezor data breach at fulfillment provider ShipMonk exposed names, addresses and phone numbers of 13,689 customers. Background

    Hardware wallet comparison 2026: Ledger vs. Trezor – new models, new risks

    Financial Products

    Memecoins on Robinhood Chain distort tokenized stock prices

    Basics

    Unit bias in crypto: Why cheap coins mislead investors

    Ray Dalio advises 10 to 15% gold and a small Bitcoin position, because he expects a US debt crisis within about three years. Minds

    Star investor Ray Dalio considers Bitcoin inferior to gold

    The Trezor data breach at fulfillment provider ShipMonk exposed names, addresses and phone numbers of 13,689 customers. Background

    Hardware wallet comparison 2026: Ledger vs. Trezor – new models, new risks

    Withdrawal freeze and the reserves behind it

    For customers, the withdrawal freeze in place since the incident weighs heaviest for now. Deposits and trading, by contrast, continue as normal. Bitget has not given a fixed date for resuming withdrawals. The company only wants to communicate deadlines once it can guarantee them. Customers can therefore trade their balances on the platform but cannot move them to their own wallet or another exchange.

    Financially, the exchange considers itself covered. Bitget's User Protection Fund is a reserve for customer losses. According to the company, it holds more than USD 464 million and covers the entire loss. On paper, the fund alone thus exceeds the loss by more than USD 110 million. Moreover, Bitget puts its own assets at over USD 1 billion.

    "Bitget has been through multiple market cycles. We will not walk away from this. We will account for every dollar and every decision with full transparency." - Gracy Chen, CEO, Bitget

    A full incident report with a root cause analysis should bring more clarity. Bitget has committed to publishing it no later than 24 hours after its first security notice. Only this report should explain how the attacker gained access to the backend system in the first place. The details of the sequence so far come from Chen's posts on X and the twelve-hour interim report.

    Parallels to Bybit and Ronin

    Bitget bases its suspicion of North Korea on two indicators. Investigators identified IP addresses linked to VPN services that North Korean hackers had used before. In addition, the attack pattern resembles earlier operations with ties to North Korea. Nevertheless, this remains a preliminary assessment by the company. Neither a government agency nor an on-chain security firm has confirmed the attribution so far.

    By comparison, the Bybit hack of February 2025 has solid documentation. Roughly USD 1.5 billion flowed out in that attack, more than four times the Bitget loss. The FBI and its reporting center IC3 attributed the Bybit hack to North Korea. Both also track the activity under the name "TraderTraitor." Earlier US advisories and security researchers link this label to the Lazarus Group. The entry point was a supply chain attack on the multisig platform Safe{Wallet}. Using manipulated software, the attackers got the legitimate signers to approve the outflow, which comes closest to the Bitget case. Bitget had supported Bybit at the time. Now Bybit CEO Ben Zhou has offered help in return. Zhou is also updating the LazarusBounty platform to trace the funds from the Bitget hack.

    Share. Facebook Twitter LinkedIn Email Telegram WhatsApp

    About the author

    Editorial Office CVJ.CH
    • Website
    • Twitter
    • LinkedIn

    Since 2018, the editorial team at Crypto Valley Journal has been reporting from Zug - the heart of Switzerland’s Crypto Valley - on Bitcoin, cryptocurrency, blockchain, and regulatory developments in digital assets. Behind the publication’s collective editorial voice is a team of writers with backgrounds in financial markets, law, and technology.

    Related Articles

    CVJ Weekly review

    Weekly review: Ethics dispute over Trump’s crypto holdings kills Clarity Act

    Bitcoin slipped to USD 74,985 after the first Fed rate hike in more than three years, one day after the Senate blocked the Clarity Act.

    Bitcoin falls after Clarity Act failure and rate hike

    FINMA is reviewing Revolut's application for a Swiss banking license that would bring salary accounts, a local IBAN and deposit insurance.

    Revolut applies for a Swiss banking license with FINMA

    The Bitget hack drained USD 351.6 million from hot and warm wallets; the exchange suspects North Korea and has halted withdrawals.
    25. September 2026

    Crypto exchange Bitget loses USD 351.6 million in a hack

    24. September 2026

    Unit bias in crypto: Why cheap coins mislead investors

    The Chainalysis Crypto Crime Report puts illicit activity below 1% of on-chain volume, countering the myth of Bitcoin as a criminal currency.
    23. September 2026

    Myth: Bitcoin and cryptocurrencies mainly serve criminal activity

    twitter image button instagram image button linkedin image button youtube image button

    About Crypto Valley Journal
    About Crypto Valley Journal

    On the pulse of the movement

    • Academy
    • Contact
    • Advertising
    • About us
    • Partner
    • Imprint
    • Privacy
    • Disclaimer
    Search

    Type above and press Enter to search. Press Esc to cancel.