Key Points
- A sophisticated attack on Bitget’s backend infrastructure resulted in $351.6 million in unauthorized transfers.
- According to CEO Gracy Chen, the breach did not involve compromised private keys, eliminating the most severe attack vector.
- The perpetrators manipulated transaction records and deceived Bitget’s authorization system into validating fraudulent transfers.
- Investigation traces point to North Korean hackers based on VPN and IP address analysis.
- The exchange’s user protection reserve of $464 million fully compensates for losses, though withdrawals are currently suspended.
Bitget, one of the world’s leading cryptocurrency trading platforms, experienced a devastating security incident resulting in $351.6 million in losses. The breach was publicly acknowledged by CEO Gracy Chen through her official X account.
According to Chen, the attack methodology differed from typical cryptocurrency heists. The perpetrators did not compromise private keys—the cryptographic credentials that function as master access codes to digital asset wallets.
The attackers penetrated a backend component within Bitget’s wallet management system. This foothold enabled them to manipulate transaction records and authorization requests.
Attack Methodology Explained
Chen described the intrusion using an analogy: imagine someone inserting counterfeit withdrawal forms into a bank’s processing system while the vault itself remains locked and secure.
The threat actors fabricated transaction documentation that appeared legitimate to Bitget’s automated verification systems. These falsified requests successfully cleared the platform’s standard authorization protocols.
Security monitoring systems first identified anomalous activity at 18:31 UTC on September 24. The alert flagged suspicious outbound transactions originating from the exchange’s hot wallet infrastructure—internet-connected storage used for active trading operations.
The compromise extended beyond hot wallets to include warm wallet systems. These intermediate storage solutions bridge the gap between hot wallets and offline reserves, automatically replenishing active balances when necessary.
Chen emphasized that Bitget’s cold storage facilities remained completely untouched throughout the incident. These offline vaults maintain the highest security standard and were “fully secure” at all times.
Once detected, Bitget implemented immediate containment measures to halt further unauthorized fund movement. Chen confirmed that no additional illicit transfers have occurred since the breach was identified.
Attribution and Suspected Perpetrators
Chen indicated that initial forensic analysis suggests North Korean state-sponsored actors may be responsible. The investigation uncovered IP addresses associated with VPN infrastructure previously linked to known North Korean hacking operations.
The attack signatures and techniques mirror previous incidents attributed to North Korean cyber warfare units. Bitget’s internal security team has ruled out the possibility of insider involvement.
An independent blockchain analyst operating under the handle Specter shared research on X connecting the stolen assets to a wallet address involved in a previous exploit. This address had been tagged as “AFX EXPLOITER” following an earlier $24 million theft.
North Korean hacking collectives have been implicated in approximately $2.02 billion worth of cryptocurrency theft throughout 2025. This figure includes the $1.5 billion Bybit breach, which U.S. federal investigators officially attributed to North Korean operatives.
Bitget has not issued a definitive attribution statement. Chen noted that investigative efforts remain ongoing.
Recovery Efforts and User Impact
Bitget maintains a dedicated User Protection Fund exceeding $464 million. According to Chen, this reserve fully covers every dollar lost in the security incident.
“User funds are safe,” Chen stated. “Your account balances are accurate and your assets are protected.”
The platform continues to process deposits and facilitate trading activity. However, withdrawal functionality has been temporarily disabled as security audits and system hardening procedures are completed.
Chen has not provided a specific timeframe for withdrawal restoration. She indicated that multiple technical teams are simultaneously addressing infrastructure vulnerabilities.
“We will announce a timeline as soon as one is confirmed,” she stated. “We will not commit to a window we cannot guarantee.”
During a live question-and-answer session on X, Chen revealed that recovery operations have already reclaimed a portion of the stolen funds. Specific recovery amounts were not disclosed.
Bitget is collaborating with blockchain protocol foundations and industry partners to trace and potentially recover additional assets. The exchange has committed to publishing a comprehensive technical post-mortem once investigative work concludes.


