Key Takeaways
- Cryptocurrency exchange Bitget suffered a devastating $351.6 million security breach when hackers infiltrated a backend system within its wallet infrastructure.
- According to CEO Gracy Chen, the breach did not involve compromised private keys, eliminating concerns about the most catastrophic form of crypto exchange hack.
- The perpetrators manipulated transaction data and deceived Bitget’s authorization mechanisms into validating fraudulent transfers.
- Investigation revealed IP address patterns consistent with VPN usage associated with North Korean cybercriminal organizations.
- The exchange’s $464 million user protection reserve fully covers losses, though withdrawal services remain suspended pending security audits.
Bitget, one of the prominent cryptocurrency trading platforms, experienced a catastrophic security breach resulting in $351.6 million in losses. The incident was publicly acknowledged by CEO Gracy Chen through a statement shared on X.
According to Chen, the compromise did not stem from stolen private keys. These cryptographic credentials function similarly to master passwords that grant complete control over digital asset movements.
Rather, the cybercriminals penetrated a backend infrastructure component connected to Bitget’s wallet management system. This access enabled them to manipulate and falsify transaction records.
The Mechanics of the Security Breach
Chen drew an analogy between the attack and an individual submitting counterfeit withdrawal documents through a financial institution’s legitimate processing channels. The security credentials themselves remained uncompromised throughout the incident.
The threat actors manufactured documentation that appeared authentic. This fraudulent paperwork was channeled through Bitget’s standard verification protocols, which mistakenly validated the requests as legitimate.
Security systems initially identified the anomaly at 18:31 UTC on September 24. Bitget’s monitoring infrastructure detected suspicious outbound transfers originating from hot wallet addressesāthese are internet-connected wallets used for routine trading operations and customer withdrawals.
The compromise extended to Bitget’s warm wallet infrastructure as well. These intermediate storage solutions bridge hot wallets and offline cold storage, automatically replenishing liquidity when necessary.
Chen emphasized that the cold storage wallets, maintained completely offline, remained untouched during the attack. She characterized these reserves as “fully secure.”
Once detected, Bitget immediately halted the unauthorized fund movements. Chen stated that additional illegitimate transfers have been prevented following the initial response.
Attribution and Suspected Perpetrators
Chen indicated that preliminary forensic analysis suggests North Korean involvement. Security researchers identified IP addresses corresponding to VPN infrastructure previously associated with a documented North Korean hacking collective.
She noted similarities between this incident and previous cyberattacks attributed to North Korean state-sponsored groups. The exchange has ruled out insider involvement based on current evidence.
An independent security analyst operating under the pseudonym Specter published findings on X that traced the misappropriated assets to a wallet address connected to a previous security incident. That particular wallet was linked to an individual identified as “AFX EXPLOITER” in a separate $24 million theft.
North Korean cybercriminal organizations have been implicated in approximately $2.02 billion worth of cryptocurrency theft throughout 2025. This figure encompasses the $1.5 billion Bybit compromise, which federal investigators formally attributed to North Korean actors.
Bitget has not issued definitive confirmation regarding the attackers’ identity. Chen stated that investigative efforts remain ongoing.
Recovery Efforts and Platform Status
Bitget maintains a User Protection Fund exceeding $464 million in reserves. Chen confirmed this fund possesses sufficient capacity to compensate for the entire loss amount.
“User funds are safe,” Chen stated. “Your account balances are accurate and your assets are protected.”
The platform continues to process deposits and facilitate trading activities. However, withdrawal functionality has been temporarily disabled while comprehensive security assessments are conducted.
Chen refrained from providing a specific timeframe for restoring withdrawal services. She indicated that multiple specialized technical teams are simultaneously addressing various aspects of the security remediation.
“We will announce a timeline as soon as one is confirmed,” she stated. “We will not commit to a window we cannot guarantee.”
During an interactive Q&A session on X, Chen revealed that portions of the stolen cryptocurrency have already been retrieved. Specific recovery amounts were not disclosed.
Bitget is collaborating with blockchain network foundations and industry partners on fund recovery initiatives. The exchange has committed to publishing a comprehensive technical analysis once investigative procedures conclude.





