Bitget Hack: $351.6m Stolen From Hot Wallets, Exchange Says User Funds Safe
By Aboki Forex —
Cryptocurrency exchange Bitget has disclosed that approximately $351.6m was lost after hackers gained unauthorised access to part of its wallet infrastructure. The exchange said its security systems detected unauthorised transfers from some hot wallets at 18:31 UTC on Thursday, September 24, prompting it to activate emergency response protocols.
In an initial security notice signed by CEO Gracy Chen on Thursday, Bitget said the breach was limited to part of its hot and warm wallet layers. Its cold wallets remained secure. “Estimated funds affected: approximately $351.6 million,” Bitget said.
Withdrawals suspended, user fund covers loss
Bitget said withdrawals were temporarily suspended as a precaution. Deposits and trading remained operational. It assured users that the loss was covered by its User Protection Fund, which it said held more than $464m. “User funds are safe. The full amount of this loss falls within the coverage of Bitget’s User Protection Fund, which currently holds over $464 million,” Bitget said.
In a subsequent update, Chen disclosed more details about how the attackers moved the funds. She said they had compromised a critical backend system within Bitget’s wallet infrastructure. “The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” she said.
Chen said the investigation had ruled out a compromise of private keys and that further unauthorised transfers had been prevented. “Private key compromise has been ruled out, this excludes the more severe risk scenarios. Loss containment is confirmed. No further unauthorized transfers are possible,” she said.
The specific method used to gain access to the backend system remained under investigation. A full technical report will be released once findings are confirmed.
Affected assets and networks
Bitget later disclosed that the affected assets included ETH, XRP, BNB, AVAX, USDT, USDC and other tokens across the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base networks. “All on-chain cold wallets have been confirmed secure and unaffected,” Chen said during a livestream with users.
She also said Bitget had contacted the foundations of the affected blockchain networks. Some confirmed the freezing of wallet addresses linked to the attackers. On the possible identity of the attackers, Chen said Bitget’s analysis found similarities with known North Korean hacking operations. “Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations,” she said.
She added that the exchange had reported the matter to relevant institutions and was cooperating with a global investigation. Chen also clarified that Bitget Wallet, the exchange’s decentralised wallet product, was not affected. “Bitget Wallet operates completely independently from Bitget exchange infrastructure, and this incident has no impact on it whatsoever,” she said.
No withdrawal timeline yet
On the restoration of withdrawals, Bitget said several technical teams were working on system remediation and security hardening. It would not announce a timeframe until one was confirmed. “Our goal is to complete a full recovery as soon as possible. We will announce the specific time window immediately upon confirmation. We will not commit to timelines we cannot deliver on,” Chen said.
Bitget said it had also notified law enforcement agencies and on-chain security firms. It is pursuing available channels to contain the incident and recover the affected assets. The exchange had earlier said it would provide hourly updates and publish a full incident report, including its root-cause analysis and corrective actions, within 24 hours.