Fraudsters hack Bitget wallets, steal $351.6m

Cryptocurrency exchange Bitget has disclosed that hackers stole approximately $351.6m after gaining unauthorised access to part of its wallet infrastructure.
The exchange said its security systems detected unauthorised transfers from some of its hot wallets at 18:31 UTC on Thursday, September 24, prompting the activation of its emergency response protocols.
In an initial security notice signed by Bitget CEO, Gracy Chen, the exchange said the incident was restricted to part of its hot and warm wallet layers, while its cold wallets remained secure.
“Estimated funds affected: approximately $351.6 million,” Bitget said.
As a precaution, the exchange temporarily suspended withdrawals but kept deposits and trading services operational.
Bitget also assured users that the stolen funds were covered by its User Protection Fund, which it said held more than $464m.
“User funds are safe. The full amount of this loss falls within the coverage of Bitget’s User Protection Fund, which currently holds over $464 million,” Bitget said.
In a subsequent update, Chen provided further details on how the attackers moved the funds, saying they had compromised a critical backend system within Bitget’s wallet infrastructure.
“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” she said.
According to Chen, the investigation had ruled out the compromise of private keys and confirmed that additional unauthorised transfers had been stopped.
“Private key compromise has been ruled out, this excludes the more severe risk scenarios. Loss containment is confirmed. No further unauthorized transfers are possible,” she said.
However, Bitget said investigations were still ongoing to determine the precise method used by the attackers to gain access to the backend system.
The exchange said it would publish a full technical report after the findings had been confirmed.
The affected assets included ETH, XRP, BNB, AVAX, USDT, USDC and other tokens across the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base networks.
“All on-chain cold wallets have been confirmed secure and unaffected,” Chen said during a livestream with users.
Chen added that Bitget had contacted the foundations of the affected blockchain networks, with some confirming that wallet addresses linked to the attackers had been frozen.
On the identity of the attackers, Chen said Bitget’s analysis had identified similarities between the incident and previously documented North Korean hacking operations.
“Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations,” she said.
She said the exchange had reported the incident to relevant institutions and was cooperating with a global investigation.
Chen also clarified that Bitget Wallet, the company’s decentralised wallet product, was not affected by the breach.
“Bitget Wallet operates completely independently from Bitget exchange infrastructure, and this incident has no impact on it whatsoever,” she said.
On the resumption of withdrawals, Bitget said several technical teams were working on system remediation and additional security measures.
The exchange said it would not provide a timeline until the restoration process had been fully confirmed.
“Our goal is to complete a full recovery as soon as possible. We will announce the specific time window immediately upon confirmation. We will not commit to timelines we cannot deliver on,” Chen said.
Bitget said it had notified law enforcement agencies and on-chain security firms while pursuing available measures to contain the incident and recover the affected assets.
The exchange had earlier said it would provide hourly updates and release a comprehensive incident report, including its root-cause analysis and corrective measures, within 24 hours.







