Cryptocurrency exchange Bitget has disclosed a $351.6 million security breach after attackers compromised part of its wallet infrastructure and transferred digital assets across several blockchains.
The exchange detected the unauthorised transfers at 18:31 UTC on September 24 and activated its emergency response procedures within minutes. Bitget said the breach affected only portions of its hot and warm wallet layers, while its cold wallets remained secure.
Bitget CEO Gracy Chen said preliminary analysis showed patterns consistent with known North Korean threat actors, although the attackers have not been conclusively identified.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Attackers compromised backend wallet infrastructure
Bitget said the attackers did not steal the private keys controlling its wallets.
Instead, the company believes a critical backend system inside its wallet infrastructure was compromised.
The attackers allegedly manipulated transaction information and caused fraudulent transfers to pass through Bitget’s own authorisation process.
That distinction is important.
A private-key compromise would mean attackers had effectively obtained the cryptographic credentials needed to control the wallets directly.
Bitget’s current assessment suggests a different failure: attackers gained enough control over internal systems to make malicious transactions appear legitimate to the infrastructure responsible for approving them.
The precise method used to enter that backend environment remains under investigation.
$351.6 million stolen across multiple blockchains
Bitget estimates that approximately $351.6 million in digital assets was affected.
The stolen assets included ETH, XRP, BNB, AVAX, USDT, USDC and other tokens. The transfers involved several networks, including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain and Base.
SecurityWeek reported that XRP accounted for the largest single-chain loss. Some blockchain organisations have also frozen wallet addresses connected to the attacker, according to Bitget.
Bitget has notified relevant authorities and is working with incident-response specialists including Google-owned Mandiant and blockchain security company SlowMist.
The company says no further unauthorised transfers are currently possible.
Withdrawals suspended while investigation continues
Bitget temporarily suspended withdrawals following the attack.
Deposits and trading remained available, and the exchange said users’ account balances continued to reflect their holdings correctly.
The company has not given a firm time for withdrawal services to resume.
It says withdrawals will be restored after its security review determines that normal operations can safely restart.
Bitget Wallet, the company’s separate self-custodial wallet product, was not affected because it operates on independent infrastructure.
User Protection Fund valued above loss
Bitget says customers will not have to absorb the $351.6 million loss.
The exchange maintains a User Protection Fund containing more than $464 million and says the full amount affected by the incident falls within the fund’s coverage.
BleepingComputer reported that the protection fund currently includes 5,500 Bitcoin.
The existence of the fund reduces the immediate risk of customers suffering losses, but the eventual financial effect on Bitget will depend on how much stolen cryptocurrency can be frozen or recovered.
Authorities and blockchain investigators are now tracking the attacker-controlled addresses.
Why North Korea is being suspected
Chen said investigators found two main indicators pointing towards possible North Korean involvement.
The first involves IP behaviour. Bitget says some of the internet infrastructure and VPN usage seen during the intrusion resembles patterns associated with North Korean hacking operations.
The second is on-chain activity.
According to Chen, the way the attackers moved assets across blockchain networks also showed similarities to previous thefts attributed to North Korean groups.
However, Bitget has not publicly released the underlying technical evidence in enough detail for outside researchers to independently verify the attribution.
SecurityWeek noted that Chen did not identify a specific North Korean threat group.
The safest description at this stage is therefore that North Korean involvement is suspected, not confirmed.
North Korean hackers have repeatedly targeted crypto firms
North Korean state-linked hacking groups have been blamed for some of the largest cryptocurrency thefts recorded in recent years.
The FBI attributed the February 2025 Bybit hack, in which about $1.5 billion was stolen, to North Korean actors. That incident remains one of the largest cryptocurrency thefts on record.
Blockchain analysis firms have also documented billions of dollars in cryptocurrency theft linked to North Korean groups over several years.
The attraction is clear: crypto assets can be transferred rapidly across borders, moved through multiple wallets and exchanged for different tokens before investigators can react.
However, blockchain transactions are also permanently recorded, allowing investigators to follow money even after attackers attempt to disguise its origin.
Backend compromise raises wider security questions
The Bitget incident highlights a cybersecurity risk beyond wallet private keys.
Crypto exchanges increasingly rely on complex internal systems that generate, verify and approve transactions before they are signed and broadcast to a blockchain.
Protecting the cryptographic key alone may therefore not be enough.
If an attacker gains control of the systems that decide what should be signed, the exchange’s own security process can potentially be turned against it.
That appears to be the central question in Bitget’s investigation.
The company has promised further information once it completes its root-cause analysis.
What this means for you: Bitget says customer balances are protected and its protection fund can cover the loss, but withdrawals remain paused while the investigation continues. Users should rely only on official Bitget updates and avoid messages claiming they need to move funds or reconnect wallets because of the breach.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics