Bitget Crypto Exchange Suffers $351.6 Million Breach, North Korea Suspected
Cryptocurrency exchange Bitget has disclosed a significant security breach, resulting in the loss of approximately $351.6 million from its hot and warm wallet infrastructure. The incident, detected on Thursday, September 24, at 18:31 UTC, prompted the immediate activation of emergency response protocols by the exchange
Bitget CEO Gracy Chen confirmed in an initial security notice that while hot and warm wallet layers were compromised, the exchange’s cold wallets remained secure and unaffected. Withdrawals were temporarily suspended as a precautionary measure, though deposits and trading continued to operate normally.
User Funds Secured by Protection Fund
Addressing user concerns, Bitget assured its community that all affected funds are fully covered by its User Protection Fund, which currently holds over $464 million. “User funds are safe,” Bitget stated, emphasizing that the entire loss falls within the fund’s coverage.
Attack Vector: Backend System Compromise
Further details provided by Chen clarified the nature of the attack. She explained that attackers compromised a critical backend system within Bitget’s wallet infrastructure. This enabled them to spoof transaction data and trigger unauthorized fund transfers. Crucially, the investigation has ruled out a compromise of private keys, a more severe scenario for crypto security. Bitget confirmed that further unauthorized transfers have been prevented, indicating successful loss containment.
The affected digital assets span a wide range of popular cryptocurrencies and networks, including ETH, XRP, BNB, AVAX, USDT, and USDC across the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base networks.
North Korean Link and Global Investigation Underway
Bitget’s internal analysis suggests a possible connection to North Korean hacking operations. Chen noted that “Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations.” The exchange is actively cooperating with a global investigation and has reported the matter to relevant law enforcement agencies and on-chain security firms. They are pursuing all available channels to contain the incident and recover the stolen assets.
Bitget has also reached out to the foundations of the affected blockchain networks, some of which have already confirmed the freezing of wallet addresses linked to the attackers.
Recovery Efforts and Communication
It is important to note that Bitget Wallet, the exchange’s decentralized wallet product, operates independently and was not impacted by this incident. Several technical teams are currently working on system remediation and security hardening to restore full functionality, including withdrawals.
Bitget has committed to providing hourly updates and will release a comprehensive incident report, including a root-cause analysis and corrective actions, within 24 hours of confirming all findings. While a specific timeframe for withdrawal restoration has not yet been announced, the exchange aims for the earliest possible full recovery.
