Everything We Know About Bitget’s Massive $351M Hack

Everything We Know About Bitget’s Massive $351M Hack


Key Takeaways

The exchange has confirmed the breach, frozen withdrawals and begun working with law enforcement and onchain security firms. CEO Gracy Chen says customer balances remain intact, cold wallets escaped untouched and Bitget’s more than $464 million User Protection Fund is large enough to swallow the entire loss.

How the Bitget Hack Unfolded

On Thursday, Bitget disclosed that its security systems detected unauthorized transfers from some of its hot wallets at 18:31 UTC on Sept. 24. Emergency procedures were activated within minutes, suspicious addresses were identified and reported, and law enforcement and blockchain security firms were contacted.

The damage was substantial. Bitget estimates that approximately $351.6 million was affected, but says only portions of its hot and warm wallet layers were compromised. The company operates a three-tier wallet architecture and maintains that its cold wallets remain fully secure. Withdrawals were subsequently suspended across the platform as a precaution. Deposits and trading remain operational, while Bitget detailed that customer account balances continue to accurately reflect users’ assets.

That distinction matters because the exchange is effectively saying this is a corporate balance-sheet loss rather than one it intends to pass through to customers. Chen explained in several X posts that customers would remain whole. The exchange founder said Bitget’s User Protection Fund currently holds more than $464 million, putting the $351.6 million estimated loss about $112 million below the fund’s stated value. The exchange says the entire incident, therefore, falls well within the fund’s coverage.

“We will not run from this,” Bitget said in its official notice, promising that “every dollar and every decision” would be accounted for.

The Blockchain Saw Trouble Before Bitget Spoke

Before Bitget confirmed anything, blockchain observers were watching millions of dollars pour from exchange-labeled wallets. The early picture centered on roughly $150 to more than $170 million of assets moving to fresh addresses. That is not the behavior of someone shopping around for the best execution.

As the picture widened, onchain researchers tracked assets across several networks. Lookonchain’s later tally included approximately 102.93 million XRP worth $157.5 million, 31,890 ETH worth $85.8 million, $34.75 million USDT, $21.05 million USDC, $19.67 million USDT0, 3,000 XAUt, 12,719 BNB, 821,012 AVAX and 20.59 million TRX.

A large portion of the assets movable through Ethereum Virtual Machine-compatible networks was rapidly consolidated and converted into ethereum. Lookonchain estimated that the component eventually reached roughly 67,982 ETH.

The difference between that figure and Bitget’s $351.6 million estimate is important. The roughly $183 million number captured a prominent cluster visible to onchain trackers, while Bitget’s figure reflects its accounting across the affected infrastructure and additional blockchains, including the enormous XRP position. In other words, the first blockchain alarms and onchain investigators caught part of the fire, not the whole building.

Bitget Says Its Private Keys Were Not Stolen

The developing technical picture may be the most consequential piece of the incident. In a subsequent update, Chen explained that Bitget’s private keys were not compromised. Instead, according to her preliminary description, attackers compromised a critical backend component within the exchange’s wallet infrastructure and were able to forge or spoof transaction data that entered Bitget’s ordinary authorization and signing process.

Gracy Chen’s X post on Thursday evening.

That would represent a very different attack from simply stealing a private key. If Bitget’s account is confirmed, the system designed to decide what should be signed was manipulated into authorizing transactions that should never have existed. The keys could therefore remain technically secure while the infrastructure feeding instructions to them failed.

Chen said the compromise has been contained and further unauthorized transfers are no longer possible. Bitget, however, has stopped short of formally declaring a final attack vector until its investigation is complete. That leaves plenty of unanswered questions. Investigators still need to establish how the backend was penetrated, what privileges the attackers obtained, why existing controls did not reject the transactions, and whether additional authentication or transaction-policy safeguards could have stopped them.

Did North Korea’s Lazarus Group Attack Bitget?

Then there is the North Korea question. Reports and social media posts following Chen’s live update have connected preliminary IP or routing information with infrastructure patterns previously associated with North Korean attackers. That quickly produced speculation that the Lazarus Group may be responsible. For now, that is exactly what it is: speculation.

The coincidences are impossible to ignore. North Korean hackers, particularly the state-funded Lazarus Group, have been blamed for some of crypto’s largest thefts, most notably the approximately $1.5 billion Bybit breach in February 2025. Until investigators publish technical indicators, laundering patterns or other evidence tying Bitget’s attacker to a known group, however, Lazarus should remain a hypothesis rather than a conclusion.

What Happens to Bitget Users Now?

For customers, the immediate problem is withdrawals. They remain disabled while Bitget conducts its security review. The exchange says its teams are simultaneously fixing the affected infrastructure and preparing to restore withdrawals, but Chen has declined to provide a reopening time she cannot guarantee. Deposits and trading remain available.

The protection fund is now also under a microscope. Bitget says its more than $464 million value comfortably covers the estimated loss, although the notices released so far do not amount to an independent, real-time audit of the fund’s composition or segregation.

Recovery is another matter. Fiat-pegged stablecoins such as USDT and USDC can potentially be frozen through issuer-controlled contracts when assets remain identifiable. Native ethereum sitting in fresh wallets is considerably harder to stop, making the attacker’s rapid conversion into ETH particularly significant.

Chen has been updating the community regularly, and she stressed that the exchange is working with Mandiant and Slowmist on a full investigation into the incident. She reiterated once again that “user balances remain intact” and said Bitget’s User Protection Fund will cover losses stemming from the breach. Chen further added that Bitget Wallet was unaffected because its self-custodial infrastructure is separate from the exchange.

This incident also should not be confused with Bitget’s roughly $100 million April 2025 market-making, bot and arbitrage episode. That was a separate event with a different mechanism. The next major piece of evidence should come directly from Bitget. The exchange has promised hourly updates and a full incident report within 24 hours of its initial notice, including root-cause analysis and corrective measures.

Until then, three numbers tell most of the story: $351.6 million was affected, more than $464 million supposedly stands behind it, and Bitget users are waiting for withdrawals to come back online. The fourth number, how much of the stolen crypto can actually be recovered, remains anyone’s guess.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *

Pin It on Pinterest