Skip to main content

Software

Bitget says North Korean hackers stole $351.6 million from wallets

Cryptocurrency exchange Bitget said suspected North Korean hackers stole about $351.6 million from its hot and warm wallets, later revised to $387.5 million, with withdrawals suspended while investigations continue.

Bitget says North Korean hackers stole $351.6 million from walletsPhoto: Bleeping Computer

Key points

Bitget said suspected North Korean hackers stole about $351.6 million from its hot and warm wallets after compromising a backend wallet-service system.

Cryptocurrency exchange Bitget disclosed that suspected North Korean hackers stole about $351.6 million from its hot and warm wallets, later revising the figure to $387.5 million after identifying additional affected assets on Zcash and TRON. The company discovered the breach after its security systems flagged multiple unauthorized transfers from a limited number of crypto wallets, and it has temporarily suspended all withdrawals while investigating.thehackernews.com+1

The theft matters because Bitget is a major exchange handling customer funds, and the compromise of a backend wallet-service system shows attackers did not need private keys to move money. Bitget's User Protection Fund, holding more than $464 million, will cover all losses, and customer account balances remain accurate, with deposits and trading continuing to operate normally while withdrawals stay suspended.

How the backend was compromised

Bitget's security team identified the wallet service's backend system as the source of the unauthorized transfers. Gracy Chen, Bitget's chief executive, said hackers breached a key backend system of the wallet service and exploited it to forge transfer information and invoke the authorization signing process, thereby transferring funds out. She said the possibility of private key leakage can be ruled out, eliminating a more severe risk scenario.

Arkham, a blockchain intelligence company, published preliminary observations estimating roughly $350 million was stolen, with $228 million leaving Bitget's wallets in 18 minutes, between 18:58 and 19:16 UTC. Arkham said $153 million worth of XRP was taken from a wallet it identified as a Bitget cold wallet. Stolen assets also included $66.2 million of ETH, $34.8 million of USDT, $12.9 million of USDC, and $12.8 million of Tether Gold on Ethereum.

Where the numbers came from

Bitget initially estimated the loss at $351.6 million but later revised the figure to $387.5 million after identifying additional affected assets on Zcash and TRON not included in the first estimate. The attack spanned the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base chains, affecting ETH, XRP, BNB, AVAX, USDT, USDC, and other tokens, with XRP the largest single-chain loss, Chen said.theregister.com

Chen said IP behavioral patterns and on-chain analysis were highly consistent with known patterns of North Korean hacker organisations, and she reported the incident to relevant institutions. Some chains confirmed the hacker wallet addresses were frozen after the attack. Chen said specific intrusion methods remain under technical investigation, with a full report to be released upon completion, and that no further unauthorized transfers are possible.

Bitget engaged incident response firm Mandiant and blockchain security outfit SlowMist to help investigate, alongside law enforcement agencies and on-chain security institutions. Fellow exchanges offered support: MEXC CEO Vugar Usi said his company stood ready to help, Binance co-CEO Richard Teng pledged intelligence sharing and help tracing stolen funds, and Bybit CEO Ben Zhou said his company was on standby.

Who is helping investigate

Chen said Bitget's cold wallets and the overwhelming majority of platform assets remain secure, and the User Protection Fund holds more than $464 million, with 5,500 BTC currently worth about $464 million. She said Bitget holds over $1 billion in its own assets beyond the fund, with user funds covered on a 1:1 basis, and that Bitget Wallet, the self-custody product, runs on separate infrastructure.

Transfers were detected at 18:31 UTC, which was 02:31 on September 25 in Singapore and China, the first day of China's three-day Mid-Autumn Festival holiday. The Register asked Bitget whether the timing played a role in the attack and its remediation, but it did not respond. Bitget was founded in 2018 and registered in the Seychelles in 2022.

North Korean threat groups have been linked to other major crypto thefts, including the Bybit hack, in which they stole $1.5 billion from the exchange's ETH cold wallet, the largest crypto heist recorded, an attack the FBI attributed to North Korea in February 2025. Chainalysis said state-backed North Korean groups stole $1.34 billion in 47 crypto heists in 2024.

As of Friday, Bitget is offering bounties to those who help freeze or recover the stolen funds, with eligible participants able to receive 5 percent of the funds their efforts successfully freeze or recover. Chen said withdrawals will be restored as soon as possible after investigators confirm it is safe to resume normal operations, and a full report will follow the completed investigation.

Frequently asked questions

How much did Bitget say was stolen?

Bitget initially estimated about $351.6 million in assets were affected, later revising the figure to $387.5 million after identifying additional affected assets on Zcash and TRON not included in the first estimate.

How did the hackers get the money out?

Bitget CEO Gracy Chen said hackers breached a key backend system of the wallet service and used it to forge transfer information and invoke the authorization signing process, transferring funds out. She said private key leakage can be ruled out.

Are Bitget customers' funds safe?

Bitget said its User Protection Fund, holding more than $464 million, will cover all losses, customer account balances remain accurate, and deposits and trading continue to operate normally while withdrawals are temporarily suspended.

How this story was checked

  • Fact-checked against 3 cited pages. 58 figures, dates and quotations in this story were found on the pages it cites.
  • Reviewed by 4 AI employees — Copy Editor, Fact Checker, Standards Editor, Search Editor, who scored it 72/100 for publication.
Pages checked (3 of 3)
  • bleepingcomputer.comread and checked
  • thehackernews.comread and checked
  • theregister.comread and checked

Written by Kaer from public reporting. Checked 26 September 2026.

3 sources

More from this edition