Cryptocurrency exchange Bitget has disclosed that approximately $387.5 million in digital assets was transferred to attacker-controlled addresses following a major security breach affecting part of its wallet infrastructure.
The exchange initially estimated the value of the affected assets at about $351.6 million, but later revised the figure after further analysis of the transactions.
Key Takeaways
- Bitget detected unauthorized transfers from some of its hot wallets on September 24.
- The exchange initially estimated the affected assets at $351.6 million.
- A subsequent Bitget update put the amount transferred to attacker-controlled addresses at approximately $387.5 million.
- Bitget said its cold wallets remained secure and were not affected.
- The exchange said withdrawals were temporarily suspended while deposits and trading remained operational.
- Bitget’s CEO said the attack showed similarities to methods previously associated with North Korean hacking organizations.
- The company said investigations, asset tracing and recovery efforts were continuing.
What Happened To Bitget?
Bitget said its security systems detected unauthorized transfers at approximately 18:31 UTC on Thursday, September 24, involving some of its hot-wallet infrastructure.
The exchange subsequently activated its emergency response procedures and temporarily suspended withdrawals as a precaution.
Deposits and trading activities continued to operate, according to Bitget’s updates.
The company initially estimated that approximately $351.6 million in assets had been affected.
Following further analysis, however, Bitget said approximately $387.5 million had been transferred to addresses controlled by the attackers.
How The Bitget Attack Happened
Bitget CEO Gracy Chen said the attackers did not compromise the exchange’s private keys.
Instead, she said a critical backend system connected to the exchange’s wallet infrastructure had been compromised.
According to Chen, the attackers used the compromised system to manipulate transaction data and trigger Bitget’s authorization process, allowing the unauthorized transfers to take place.
Bitget later said the vulnerability involved in the attack had been identified and remediated.
The distinction is significant because the exchange said its cold-wallet infrastructure remained secure.
Chen said:
“Private key compromise has been ruled out.”
She also said Bitget had contained the incident and prevented further unauthorized transfers.
What Assets Were Affected?
Bitget said the affected assets included several major cryptocurrencies and stablecoins.
They included:
- Ethereum (ETH)
- XRP
- BNB
- Avalanche (AVAX)
- Tether (USDT)
- USD Coin (USDC)
- Zcash (ZEC)
- TRON (TRX)
- Other digital assets
The affected assets were distributed across several blockchain networks, including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base.
Bitget said its on-chain cold wallets had been checked and confirmed to be secure and unaffected.
What Bitget Did After The Breach
Following detection of the unauthorized transfers, Bitget activated its emergency response procedures.
The exchange temporarily suspended withdrawals while its security teams investigated the incident.
Bitget said deposits and trading remained operational.
The company also said several technical teams were working to strengthen the affected systems and prevent further unauthorized activity.
It later said the vulnerability had been identified and fixed, while security validation and other recovery procedures continued.
What Does The Breach Mean For Bitget Customers?
Bitget said customer funds remained protected.
The exchange initially stated that its User Protection Fund held more than $464 million, which it said was above the initial estimated value of the assets affected by the incident.
Bitget therefore said the loss fell within the coverage of the User Protection Fund.
However, this remains a statement from the exchange about its protection arrangements; it should not be interpreted as an independent guarantee beyond the company’s stated policy and available fund.
The temporary withdrawal suspension was the most immediate operational effect for users, while Bitget continued working on its security review and recovery process.
Bitget Suspects North Korean-Linked Hackers
Bitget has also provided an assessment of who may have been behind the attack.
Chen said the exchange’s analysis found similarities between the attack and techniques previously associated with North Korean hacking organizations.
She cited IP-behaviour patterns and on-chain analysis as part of the basis for the assessment.
However, the wording is important: Bitget suspects a North Korean connection; the company has not presented this as a conclusively established identity of the attackers.
The exchange said it had reported the incident to relevant authorities and was cooperating with a wider investigation.
Bitget Wallet Was Not Affected
Bitget also clarified that Bitget Wallet, its decentralised wallet product, was not affected by the breach.
According to the company, Bitget Wallet operates separately from the exchange’s infrastructure.
The exchange therefore said the security incident had no impact on the independent wallet product.
Investigation And Recovery Continue
Bitget said its investigation into the breach was continuing.
The company has been working with law-enforcement agencies, blockchain security firms and other relevant organisations as it attempts to trace the transferred assets.
Bitget also said some addresses linked to the attackers had been frozen following contact with the foundations of affected blockchain networks.
The exchange said security teams had identified and remediated the vulnerability, while asset tracing and recovery efforts remained ongoing.
Bitget also indicated that a detailed technical report would be published after its findings had been confirmed.
What Happens Next?
The next major developments to watch are the completion of Bitget’s technical investigation, the restoration of withdrawals and further efforts to trace or recover the affected assets.
The exchange has said it will announce a specific withdrawal-restoration timeframe once it has a definite timeframe it can confirm.
Bitget’s position is that it will not provide a restoration deadline until it is confident that the timeframe can be delivered.
The company is also expected to provide additional information about the root cause of the breach and the corrective measures implemented.
Frequently Asked Questions
How much money was stolen from Bitget?
Bitget initially estimated that approximately $351.6 million in assets were affected. The exchange later revised the figure, saying approximately $387.5 million had been transferred to attacker-controlled addresses.
Were Bitget’s cold wallets affected?
No. Bitget said its on-chain cold wallets were checked and confirmed to be secure and unaffected.
How did the hackers gain access?
Bitget said a critical backend system connected to its wallet infrastructure was compromised. The attackers allegedly manipulated transaction data and used the system to trigger the exchange’s authorization process.
Were Bitget private keys compromised?
Bitget said private-key compromise had been ruled out.
Were withdrawals suspended?
Yes. Bitget temporarily suspended withdrawals after detecting the unauthorized transfers, while deposits and trading remained operational.
Did Bitget confirm that North Korea carried out the attack?
No. Bitget’s CEO said the attack method was highly consistent with known patterns associated with North Korean hacker organisations. This is the exchange’s assessment, not a conclusively established identification of the attackers.
Was Bitget Wallet affected?
No. Bitget said its separate Bitget Wallet product was not affected by the exchange infrastructure breach.
Is Bitget investigating the incident?
Yes. The exchange said it was investigating the breach and cooperating with law enforcement, blockchain security companies and other relevant parties.
Final Takeaway
The Bitget incident began with unauthorized transfers from part of the exchange’s hot-wallet infrastructure and developed into one of the company’s most significant reported security incidents.
While Bitget initially put the affected amount at $351.6 million, its subsequent update revised the figure to approximately $387.5 million transferred to attacker-controlled addresses.
The exchange says its cold wallets and private keys were not compromised, while its investigation has focused on a compromised backend system that was used to manipulate transaction data.
Bitget has also linked the attack method to patterns associated with suspected North Korean hacking organisations, while continuing its investigation, security remediation and efforts to trace and recover the affected assets.










