Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist

Bitget, a prominent cryptocurrency exchange, has recently suffered a massive security breach at the hands of suspected North Korean hackers. The attack resulted in the loss of over $387.5 million worth of digital assets, making it one of the most significant crypto heists to date.

The incident unfolded when Bitget’s security systems flagged multiple unauthorized transfers from a limited number of cryptocurrency wallets. Upon investigation, the exchange discovered that attackers had breached its critical backend system and exploited a vulnerability to spoof transaction data, triggering the authorization process to move funds out of compromised hot and warm wallets. The hackers then transferred the stolen assets to attacker-controlled addresses.

The breach affected multiple assets across various blockchain networks, including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base chains. Bitget’s CEO, Gracy Chen, attributed the attack to North Korean hackers, citing on-chain analysis and IP behavior patterns as evidence. This is not an isolated incident, as North Korean state-sponsored threat groups have been linked to several high-profile crypto thefts in recent years.

The full extent of the damage was initially estimated at $351.6 million, but further analysis revealed that an additional $35.9 million had been stolen, bringing the total to over $387.5 million. To mitigate potential losses and prevent further unauthorized transfers, Bitget suspended all withdrawals on Thursday, leaving users unable to access their funds.

Fortunately, user account balances remain unaffected, and Bitget’s Protection Fund covers the financial impact of this incident. The exchange has also launched a Recovery Bounty Program, offering bounties of up to 5% for assistance in recovering or freezing frozen funds. This effort aims to minimize losses and prevent further damage.

In related news, North Korean hackers have been responsible for numerous significant crypto thefts, including the largest recorded heist, where they stole $1.5 billion from Bybit’s ETH cold wallet. According to British blockchain analytics firm Elliptic, these hackers have stolen over $6 billion in crypto assets since 2017.

As a result of this incident, users are advised to exercise extreme caution when interacting with cryptocurrency exchanges and be aware of potential vulnerabilities that may be exploited by attackers. Regularly monitoring account activity, enabling two-factor authentication, and keeping software up-to-date can significantly reduce the risk of falling victim to similar attacks in the future.


Source: Bleeping Computer — 2026-09-28