Bitget Hit by $351.6M Hot Wallet Breach, North Korean Hackers Suspected

Changelly
BTCC


  • Bitget detected unauthorised transfers from several hot wallets at 18:31 UTC on September 24, with the initial damage estimated at $351.6 million.
  • A North Korean connection is considered likely, with identified VPN and IP patterns matching infrastructure previously linked to a DPRK-associated hacking group.

Bitget CEO Gracy Chen announced that at 18:31 UTC on September 24, 2026, Bitget’s security systems detected unauthorised transfers from a number of its hot wallets. The emergency response team was activated within minutes. By the time the initial assessment was complete, the damage had been confirmed at approximately $351.6 million. 

The largest single theft involved XRP, with over $100 million drained. A significant volume of USDT, USDT0, USDC, and XAU was also taken, with the accumulated total across these assets swapped into approximately $170 million in ETH across multiple chains and coin types. 

On the other hand, a total of 19 transfers were executed from hot and warm wallet layers. Significantly, the cold wallets were not touched.

How the Attack Was Pulled Off?

Private key compromise has been ruled out, eliminating the more severe risk scenario. What the security team has confirmed is that hackers breached a critical backend system within Bitget’s wallet infrastructure, used it to forge transaction data, and triggered the platform’s internal authorisation signing process to move funds out. 

Tokenmetrics

User credentials were not spoofed, and private keys for hot, warm, or cold wallets were never obtained. The specific intrusion method remains under active technical investigation. Furthermore, a full root cause analysis and corrective action report will be published once the investigation is complete.

The North Korea Connection

Gracy Chen has said a North Korean link is very likely. During the investigation, the team identified IP addresses whose VPN usage patterns matched infrastructure previously associated with a specific DPRK-linked hacking group. If confirmed, this would mark another major crypto exchange breach tied to North Korean cyber operations.

What Bitget Has Done and What Happens Next?

Abnormal transfer addresses have been flagged and reported. Law enforcement agencies and on-chain security firms have been formally notified. Withdrawals have been temporarily suspended as a precautionary measure, with resumption expected anywhere from a few hours to a few days, though the team has confirmed it should not take weeks.

Deposits and trading remain fully operational. Account balances are accurate. Moreover, Bitget‘s User Protection Fund, holding 5,500 BTC worth approximately $464 million, covers the full $351.6 million loss. All fund wallet addresses are publicly verifiable on-chain. 

The fund will be replenished, with coverage terms and details to be announced separately. In addition, hourly updates are being provided across all official channels until the situation is fully resolved.

Crypto Market Highlights

Zcash (ZEC) Targets $5K by the End of 2026: Can It Make the Leap From $1.4K?





Source link

Coinmama

Be the first to comment

Leave a Reply

Your email address will not be published.


*