Bitget security breach drains $351.6M from hot wallets, cold storage safe

15 hours ago 92
Bitget security breach

Bitget is racing to contain the fallout from a major Bitget security breach that drained roughly $351.6 million from parts of its wallet infrastructure, the exchange confirmed late Thursday. The crypto platform says the damage has been contained, its cold storage was never touched, and it now suspects North Korean hackers may be behind the intrusion. For an industry still haunted by last year’s record-setting Bybit hack, the timing alone is enough to put every exchange on edge.

Key takeaways

  • Bitget confirmed a $351.6 million security incident tied to some of its hot and warm wallets on September 24, 2026.
  • The exchange says its cold wallets remain secure and were never compromised.
  • More than $170 million in assets were moved and swapped into ETH during the attack.
  • CEO Gracy Chen says private key compromise has been ruled out; attackers instead spoofed transfer data through a breached backend system.
  • Bitget’s User Protection Fund holds more than $464 million, and the exchange holds over $1 billion in proprietary capital on top of that.

Bitget Confirms $351.6 Million Hot Wallet Breach

Bitget‘s systems flagged unauthorized transfers from some exchange hot wallets at 2:31 p.m. ET on September 24, according to CEO Gracy Chen. The exchange later confirmed the total exposure at approximately $351.6 million, spread across 19 separate transfers pulled from portions of its hot and warm wallet infrastructure, CNBC reported. Affected assets reportedly included ether, XRP, USDT, USDC, Avalanche and BNB, moved across the Ethereum, XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum networks.

Early on-chain estimates had pegged the outflow at roughly $183 million, but Bitget said those calculations hadn’t captured the full scope of activity across every affected blockchain.

How the attackers moved funds into ETH

More than $170 million worth of assets were reportedly moved out and swapped into ETH during the attack, a pattern often used to consolidate stolen funds into a more liquid token before further laundering attempts. Bitget said its cold wallets remain secure, with Chen writing on X that the offline vault “remains fully secure.” That distinction matters: cold wallets are kept fully offline, while hot and warm wallets stay connected to the internet to keep liquidity flowing for everyday trading and withdrawals.

How Investigators Say the Breach Happened

Bitget’s security team says the attacker didn’t need to steal a private key at all — they forged the paperwork instead. According to preliminary findings from Bitget’s security team, attackers infiltrated a vital backend system tied to the wallet service, falsified transfer information, and set off the authorized signing workflow to withdraw funds.

She compared the method to slipping forged withdrawal slips through a bank’s own teller window: the vault keys never left the building, but someone got into the back office that prepares transfer paperwork, made it look official, and pushed it through the exchange’s normal approval process.

Private keys ruled out, North Korea suspected

Chen was direct about what didn’t happen. “Private key compromise has been ruled out,” she said. Damage mitigation measures are complete, and there is no further risk of fund loss, though the specific method of intrusion remains under investigation.

During a livestream, Chen said investigators had identified IP addresses linked to VPN services previously associated with a North Korean hacking group, and that the attack’s pattern resembled earlier operations tied to the country. She stopped short of confirming attribution with certainty, saying the exact intrusion method is still under technical review.

User Protection Fund and Bitget’s Response

Bitget says customer money isn’t at risk regardless of how the investigation concludes. The exchange’s User Protection Fund currently holds more than $464 million, an amount Chen says is enough on its own to cover the loss. User funds are fully covered by the exchange’s User Protection Fund. Beyond the fund, Bitget holds over $1 billion in proprietary capital as an additional buffer.

Withdrawals were suspended “as a precautionary measure, pending security review,” while deposits and trading continued to operate normally. Chen declined to commit to a firm restart date, saying only that withdrawals could return “within hours or days” but “shouldn’t take weeks.” She said “multiple technical teams are working in parallel on system remediation and security hardening,” adding: “We will announce a timeline as soon as one is confirmed — we will not commit to a window we cannot guarantee.” Bitget further stated that it planned to issue updates every hour and release a comprehensive incident report within 24 hours detailing the root cause and the corrective steps taken.

CEO Gracy Chen Compares Bitget to Bybit’s Recovery

Chen used the comparison to Bybit deliberately. She argued that Bitget is “certainly not ‘another FTX'” and is fully capable of withstanding a run on withdrawals, noting that Bitget’s retail business is comparable in scale to Bybit’s. If Bybit could absorb a $1.5 billion loss during its February 2025 hack and keep operating, she reasoned, Bitget can certainly absorb a loss of just over $300 million.

That comparison found some real-world backing. Bybit CEO Ben Zhou said his team was standing by to help Bitget, noting that Bitget had supported Bybit during its own $1.5 billion hack. Zhou added that Bybit is updating its LazarusBounty platform to help trace the stolen funds.

Whether the North Korea link holds up under further scrutiny remains an open question, and Bitget itself has been careful not to state it as fact. What’s clearer is the shape of the vulnerability: a backend system that trusted forged transfer data enough to trigger a real authorization process. That’s a different kind of failure than the private-key thefts that have dominated past headlines, and it’s likely to shape how exchanges audit their wallet infrastructure going forward — particularly the handoff points between hot, warm, and cold storage that Bitget says were the actual point of entry this time.

FAQ

What wallets were affected in the Bitget security breach?

Some of Bitget’s hot and warm wallets were affected, while its cold wallets remained secure and uncompromised.

Has Bitget ruled out private key theft in the breach?

Yes, Bitget’s security team confirmed that private key leakage has been ruled out as the cause of the breach.

How is Bitget protecting user funds after the breach?

Bitget’s User Protection Fund, holding over $464 million, covers user losses, and the exchange also has over $1 billion in proprietary capital.

What is the suspected origin of the hacking attack on Bitget?

Preliminary investigation points to possible involvement of North Korean hackers based on IP addresses and VPN patterns, though Bitget has not confirmed attribution with certainty.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Read Entire Article