Bitget Crypto Exchange Reports $351.6 Million Hack Linked to North Korea
Cryptocurrency exchange Bitget discloses that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. Security systems flag multiple unauthorized transfers Thursday evening, prompting the company to temporarily suspend all withdrawals while it investigates with law enforcement, on-chain security firms, and cybersecurity experts at Mandiant and SlowMist. Bitget says its cold wallets and the overwhelming majority of platform assets remain secure, and its self-custodial Bitget Wallet is unaffected because it runs on independent infrastructure.
CEO Gracy Chen explains that attackers compromise a critical backend system within the wallet infrastructure, use it to spoof transaction data, and trigger the authorization-signing process to move funds. The theft spans multiple blockchains, including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base, affecting assets such as ETH, XRP, BNB, AVAX, USDT, and USDC, with XRP representing the largest single-chain loss. Chen links the attack to North Korean hackers based on IP behavior patterns and on-chain analysis, and notes that several chains confirm the hacker wallet addresses are already frozen.
Bitget assures customers that account balances remain accurate and that deposits and trading continue operating normally. The company's User Protection Fund, holding 5,500 BTC worth roughly $464 million, covers all losses from the incident. Bitget reports the breach to relevant institutions and cooperates fully in a global investigation, though the specific method of system intrusion remains under active investigation, and no further unauthorized transfers are possible.