Crypto exchange Bitget has confirmed a USD 351.6 million hack that hit parts of its hot and warm wallets. The company suspects a North Korean hacker group behind the attack and has suspended withdrawals until further notice.
Bitget is a centralized crypto exchange where customers deposit funds, trade with them and withdraw assets to their own addresses. The platform spreads its holdings across three tiers. Always-connected hot wallets handle daily operations, warm wallets serve as a buffer and cold wallets have no internet connection. As a result, the closer a tier sits to day-to-day business, the larger its attack surface. At 18:31 UTC on 24.09.2026, Bitget's security systems flagged unauthorized outflows from the two connected tiers. A few hours later, CEO Gracy Chen confirmed the incident on X. On-chain analysts initially estimated the outflow at USD 180 million. However, the confirmed total came in at roughly twice that figure. The losses span seven chains: Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Smart Chain and Base.
Bitget hack: backend manipulation instead of stolen keys
Initially, Chen declined to speculate on the attack vector before the investigation was complete. The sequence of events is now becoming clearer. The attacker gained access to a critical backend system in the wallet infrastructure. There, the attacker forged transfer data and thus got Bitget's regular authorization process to approve the outflows. The exchange rules out theft of private keys.
This distinction is key to assessing the case. With a stolen key, an attacker can sign transfers directly. In Bitget's case, however, signing stayed with the exchange. The approval therefore went through the usual controls. Only the data behind it came from the attacker. Consequently, even well-secured key custody offers no protection when the upstream system supplies false transfer data. Not least for institutional clients, reviewing internal approval processes now carries more weight.
According to the exchange, Bitget's cold wallets remain untouched and secure. The attack hit only part of the hot and warm tier. Affected assets include ETH, XRP, USDT, USDC, AVAX and BNB. An exchange that supports many chains must keep connected holdings on each of them for withdrawals. This increases the number of attack points. Bitget reported its largest loss on a single chain on the XRP Ledger. In addition, the issuers of the stablecoins USDT and USDC can freeze affected balances.
From USD 170 million to USD 351.6 million
The first reports spoke of more than USD 170 million flowing from Bitget wallets to an unidentified address. These early on-chain analyses covered only some of the affected chains at first. The cross-chain analysis finally produced the USD 351.6 million figure that Chen confirmed. Consequently, there is no contradiction between the two numbers.
At the same time, the attacker tried to shield the loot from a freeze. A newly created wallet with the address prefix "0xe410" swapped roughly USD 19.67 million in USDT0 for 7,111 ETH. The trade took only a few minutes. To do so, the wallet accepted a premium of about 5% above the market price. That works out to just under USD 1 million. Speed apparently outweighed price. After all, unlike with stablecoins, nobody can freeze an ETH balance after the fact.
Still, the plan did not fully work. In its twelve-hour interim report, the exchange said some affected chain foundations had frozen the attacker's addresses. Chain foundations are the organizations behind individual networks, and some of them can block addresses on their chain. Yet Bitget does not name the chains or the amounts at stake. As a result, nobody can say how much of the USD 351.6 million actually remains stuck.
Withdrawal freeze and the reserves behind it
For customers, the withdrawal freeze in place since the incident weighs heaviest for now. Deposits and trading, by contrast, continue as normal. Bitget has not given a fixed date for resuming withdrawals. The company only wants to communicate deadlines once it can guarantee them. Customers can therefore trade their balances on the platform but cannot move them to their own wallet or another exchange.
Financially, the exchange considers itself covered. Bitget's User Protection Fund is a reserve for customer losses. According to the company, it holds more than USD 464 million and covers the entire loss. On paper, the fund alone thus exceeds the loss by more than USD 110 million. Moreover, Bitget puts its own assets at over USD 1 billion.
"Bitget has been through multiple market cycles. We will not walk away from this. We will account for every dollar and every decision with full transparency." - Gracy Chen, CEO, Bitget
A full incident report with a root cause analysis should bring more clarity. Bitget has committed to publishing it no later than 24 hours after its first security notice. Only this report should explain how the attacker gained access to the backend system in the first place. The details of the sequence so far come from Chen's posts on X and the twelve-hour interim report.
Parallels to Bybit and Ronin
Bitget bases its suspicion of North Korea on two indicators. Investigators identified IP addresses linked to VPN services that North Korean hackers had used before. In addition, the attack pattern resembles earlier operations with ties to North Korea. Nevertheless, this remains a preliminary assessment by the company. Neither a government agency nor an on-chain security firm has confirmed the attribution so far.
By comparison, the Bybit hack of February 2025 has solid documentation. Roughly USD 1.5 billion flowed out in that attack, more than four times the Bitget loss. The FBI and its reporting center IC3 attributed the Bybit hack to North Korea. Both also track the activity under the name "TraderTraitor." Earlier US advisories and security researchers link this label to the Lazarus Group. The entry point was a supply chain attack on the multisig platform Safe{Wallet}. Using manipulated software, the attackers got the legitimate signers to approve the outflow, which comes closest to the Bitget case. Bitget had supported Bybit at the time. Now Bybit CEO Ben Zhou has offered help in return. Zhou is also updating the LazarusBounty platform to trace the funds from the Bitget hack.








