Crypto Exchange Bitget Hit with $351.6 Million Hack, Suspected North Korean Attackers Blamed
In a massive cybersecurity breach, cryptocurrency exchange Bitget has fallen victim to a sophisticated hack that has resulted in the theft of approximately $351.6 million from its hot and warm wallets. The attack is believed to have been carried out by suspected North Korean hackers, who have previously been linked to several other major crypto heists.
According to Bitget’s CEO Gracy Chen, the attackers compromised a critical backend system within the exchange’s wallet infrastructure, allowing them to spoof transaction data and trigger the authorization process to move funds out. Chen stated that no further unauthorized transfers are possible, but the specific method of system intrusion remains under active investigation.
The breach is particularly concerning due to its scale and sophistication. Bitget has temporarily suspended all withdrawals while it works with law enforcement agencies, on-chain security institutions, and cybersecurity experts from Mandiant and SlowMist to investigate the incident. The exchange has also assured users that their customer account balances remain accurate, and deposits and trading continue to operate normally.
One of the most striking aspects of this attack is its similarity to previous North Korean hacking operations. Chen confirmed that the hacker wallet addresses have been frozen since the attack, and that some chains have linked the theft to North Korean hackers based on IP behavior patterns and on-chain analysis. This suggests a level of sophistication and coordination among the attackers.
The incident also highlights the ongoing threat posed by state-sponsored cybercrime groups. Chainalysis reported in 2024 that state-backed North Korean hacking groups stole $1.34 billion in crypto heists throughout the year, while Elliptic estimated that North Korean hackers have stolen over $6 billion in crypto assets since 2017.
Bitget has stated that its self-custodial Bitget Wallet was not affected by the attack, as it operates on infrastructure independent of the exchange and was not impacted by the breach. The User Protection Fund, which currently holds over $464 million, will cover all losses resulting from the hack. However, this incident serves as a stark reminder of the ongoing risks faced by cryptocurrency exchanges and their users.
As cybersecurity professionals continue to investigate the attack, it is essential for users to remain vigilant and take steps to protect themselves against similar threats. This includes regularly monitoring account balances, enabling two-factor authentication, and keeping software and systems up-to-date with the latest security patches.
Source: Bleeping Computer — 2026-09-25