Wealthier Today logoWealthier
Today
Bitget Loses $351.6M in Hot Wallet Hack: What Users Need to Know

Bitget Loses $351.6M in Hot Wallet Hack: What Users Need to Know

/4 min read
  • Bitget says about $351.6 million in crypto was affected by unauthorized transfers from its hot and warm wallets, while customer balances remain intact and withdrawals are temporarily suspended.

Crypto exchange Bitget suffered a security breach on Sept. 24 that affected approximately $351.6 million in digital assets, according to the exchange, after its security systems detected unauthorized transfers from a limited number of hot wallets.

Bitget said its cold wallets and the overwhelming majority of platform assets remain secure. The exchange also said customer account balances are accurate, deposits and trading remain operational, and the loss falls within its User Protection Fund, which holds more than $464 million.

The incident was detected at 18:31 UTC, according to Bitget's security notice. The exchange immediately activated its emergency response procedures, flagged the relevant addresses, and temporarily suspended withdrawals while investigators review its systems.

Bitget CEO Gracy Chen later said preliminary analysis points toward a North Korea-linked hacking operation, but the attribution remains an investigation rather than a confirmed finding by law enforcement. CNBC also reported that Bitget suspects North Korea was behind the attack.

The distinction matters. Bitget has confirmed the unauthorized transfers and the amount affected, but the identity of the attackers and the precise method used to gain access remain subject to investigation.

What Happened in the Bitget $351.6 Million Hack?

Bitget initially described the incident as unauthorized transfers involving part of its hot-wallet infrastructure. Its latest security notice says the affected assets were limited to portions of its hot and warm wallet layers, while its cold wallets remained secure. The exchange operates a three-tier wallet architecture, according to Bitget.

A subsequent preliminary investigation reported by CoinDesk found that attackers appear to have compromised a backend system inside Bitget's wallet infrastructure, spoofed transaction information, and then triggered the exchange's own authorization process.

Bitget said private keys were not compromised, according to the report, although investigators were still determining exactly how the attackers entered the backend system. The breach involved multiple blockchain networks and assets. BleepingComputer reported that affected networks included Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain and Base, with ETH, XRP, BNB, AVAX, USDT, USDC and other tokens among the assets affected.

Independent on-chain researchers identified significant movements of XRP and Ethereum following the breach. CCN reported that approximately 102.93 million XRP, valued at about $157.5 million at the time, and 31,890 ETH, valued at roughly $85.8 million, were among the largest identified transfers.

Bitget has not yet published a complete forensic report explaining the initial point of compromise.

That leaves an important distinction between the $351.6 million affected by the breach and customer funds held on the platform. Bitget says the affected assets are covered by its User Protection Fund and that customer account balances have not been reduced.

Is Bitget's User Protection Fund Enough to Cover the Hack?

Bitget says yes, based on the current figures. The exchange's User Protection Fund held more than $464 million when the incident occurred, compared with approximately $351.6 million in affected assets. That leaves a reported coverage buffer of roughly $112 million based on those figures.

Bitget also says deposits and trading remain fully operational, although withdrawals are paused until the security review is completed. The exchange said it will restore withdrawal services once investigators determine that it is safe to do so.

The exchange has brought in law enforcement agencies and on-chain security firms as part of the investigation. BleepingComputer reported that Mandiant and SlowMist were among the cybersecurity and blockchain-security specialists assisting with the response.

Why North Korea Is Being Investigated

Bitget's preliminary assessment has drawn attention because North Korean cyber groups have been repeatedly linked to major cryptocurrency thefts.

Chen said the attack showed patterns consistent with known North Korean hacking organizations, including similarities in IP behavior and VPN usage. Cointelegraph reported that Chen cited preliminary IP evidence when discussing the suspected connection.

That allegation has not yet reached the same level of official attribution as the $1.5 billion Bybit hack in February 2025. In that case, the FBI formally attributed the theft to North Korea and identified the activity as part of its TraderTraitor campaign.

The Bybit case demonstrates why attribution can take time. Blockchain investigators initially traced the stolen assets and linked the attack to North Korean actors, while the FBI later issued an official attribution.

Tags

Bitget HackBitget $351.6M HackBitget Security BreachBitget Hot Wallet HackCrypto Exchange HackNorth Korea Crypto HackCrypto SecurityBitget User FundsCryptocurrency HackBitget WithdrawalsCrypto news
Scott Matherson

Scott Matherson

Scott Matherson is a markets writer at Wealthier Today who helps readers understand investing trends, fintech, Bitcoin, digital assets, policy, and modern money decisions.

Share this article

Disclaimer: This article is for informational purposes only and should not be considered financial, investment, legal, or tax advice. Always conduct your own research and consult a qualified professional before making financial decisions.