Bitget hack: $351.6M stolen, North Korea suspected
Cryptocurrency exchange Bitget has disclosed that attackers took $351.6 million from its hot and warm wallets. These are wallets that stay connected to the platform's systems for day-to-day operations. The company links the theft to North Korean hackers.
Bitget spotted the breach on Thursday evening, when its security systems flagged several unauthorized transfers from a small number of crypto wallets. It has paused all withdrawals while it investigates. Law enforcement agencies, on-chain security institutions, and experts from Mandiant and SlowMist are assisting with the investigation.
Cold wallets and customer balances untouched
The exchange says the damage is limited to part of its infrastructure. Its cold wallets, which are kept offline, were not affected. According to the company, most of the assets on the platform are also safe.
Bitget also runs a self-custodial product, Bitget Wallet, in which users hold their own keys. That product runs on infrastructure separate from Bitget Exchange, and the company says the attack did not reach it.
Losses will be paid from Bitget's User Protection Fund. The fund holds 5,500 BTC, worth roughly $464 million at current prices.
"Based on our current assessment, approximately $351.6 million in assets were affected. Bitget's cold wallets and the overwhelming majority of platform assets remain secure and unaffected," the company said.
"The incident falls within the coverage of Bitget's User Protection Fund, which currently holds more than $464 million. Customer account balances remain accurate, and deposits and trading continue to operate normally."
Seven chains, several assets
Bitget CEO Gracy Chen said the stolen funds moved across the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base chains. The attackers took ETH, XRP, BNB, AVAX, USDT, USDC and other tokens. XRP was the largest loss on any single chain.
According to Chen, some chains have frozen the wallet addresses used by the attackers since the theft took place.
She tied the attack to North Korea based on the evidence gathered so far.
"Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations. We have reported to relevant institutions and are fully cooperating in conducting a global investigation," Chen said.
A compromised backend system
Bitget has not yet explained how the attackers got into the system. What it has described is the general mechanism. The intruders gained access to a key backend wallet-service system and used it to forge transfer information. The forged data then triggered the exchange's own authorization-signing process, which sent the funds out.
"The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation," Chen said.
In its latest update, the exchange said withdrawals will resume as soon as investigators confirm it is safe to restart normal operations. It gave no timeline.
A familiar suspect
North Korean threat groups have been linked to many of the largest thefts in the crypto sector. The biggest was the Bybit hack, in which attackers stole $1.5 billion from that exchange's ETH cold wallet. It remains the largest crypto heist on record.
Blockchain analysis firm Chainalysis reported two years ago that state-backed North Korean groups stole $1.34 billion in 47 crypto heists during 2024. In February 2025, Elliptic estimated that North Korean hackers had stolen more than $6 billion in crypto assets since 2017. The proceeds were reportedly spent on the country's ballistic missile program.
Why It Matters
The way the funds were moved stands out. The attackers do not appear to have simply stolen private keys. Bitget's description suggests they got the exchange's own signing process to approve forged transfers. This points to a weakness in the systems around the wallets, and more is not always better when it comes to key storage alone. Exchanges that rely on automated authorization may want to check how much they trust data coming from their backend services.
For customers, the protection fund and the unaffected cold wallets limit the direct impact. The suspended withdrawals are still the practical problem for now.
It is worth watching whether Bitget publishes details of the intrusion method, and whether more of the stolen funds get frozen as they move across chains. If the North Korea attribution holds, the incident adds to a pattern that has turned crypto exchanges into a steady source of revenue for the regime.
Sponsored Recommended for you – discover more →
