Bitget Loses $352 Million In Massive Crypto Hack. North Korea Is Now Under Suspicion
The exchange temporarily suspended withdrawals after attackers breached part of its hot and warm wallet infrastructure, while cold wallets remained secure.

Crypto exchange Bitget lost about $351.6 million in digital assets after attackers breached part of its wallet infrastructure, prompting the company to suspend withdrawals while investigators examine evidence that may point to North Korean hackers.
The exchange detected unauthorized transfers at 18:31 UTC on Thursday and activated its emergency response procedures within minutes, according to an official Bitget security notice. The breach affected portions of its hot and warm wallet infrastructure, while the company's cold wallets remained secure.
Bitget CEO Gracy Chen said in a livestream on X that investigators had identified internet protocol addresses connected to VPN services previously associated with a North Korean hacking group. She said elements of the attack also resembled patterns seen in earlier operations linked to North Korea.
The finding remains preliminary, and Bitget has not said that North Korea's involvement has been independently established. The company has notified law enforcement agencies and on-chain security firms, while the specific method used by the attacker to initially enter its systems remains under investigation.
Chen said investigators had determined that the attacker compromised a critical backend system in Bitget's wallet infrastructure, spoofed transfer information and then triggered the platform's authorization-signing process. She said a compromise of private keys had been ruled out and that the breach had been contained.
The incident involved 19 unauthorized transfers from parts of Bitget's hot and warm wallet systems, Chen said. Assets affected included ether, XRP, Tether's USDT, USD Coin, Avalanche and BNB across several blockchain networks, including Ethereum, XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum.
Bitget's initial disclosure put the total value of affected assets at approximately $351.6 million. The company said it had identified and flagged addresses associated with the unauthorized transfers and reported them as part of its response.
Withdrawals were temporarily suspended while Bitget conducted its security review. Deposits and trading remained operational, and the company said customer account balances continued to display accurately.
Bitget said the entire estimated loss falls within the coverage of its User Protection Fund, which was valued at more than $464 million following the breach.
The company created the fund as a separate reserve intended to provide additional protection for customer assets and has committed to maintaining its value above $300 million. Bitget's most recent Proof of Reserves report, published Sept. 17, showed an overall reserve ratio of 135%.
That report was Bitget's 46th Proof of Reserves update since it started publishing the disclosures in December 2022. The company expanded the latest report to cover 19 assets and said it aims to maintain reserves of at least 1:1 against corresponding customer assets.
A protection fund is separate from Proof of Reserves: the former is an exchange-controlled financial reserve, while the latter provides a snapshot of assets held against customer balances.
The investigation comes roughly 19 months after hackers stole about $1.5 billion in virtual assets from crypto exchange Bybit in one of the industry's largest security breaches.
In that case, the Federal Bureau of Investigation formally attributed the February 2025 theft to North Korea. The FBI identified the activity as "TraderTraitor" and said the attackers rapidly converted some of the stolen assets into bitcoin and other cryptocurrencies before dispersing them across thousands of blockchain addresses.
© Copyright IBTimes 2026. All rights reserved.
























