Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$83,930▼ 0.58%ETH$2,693▲ 0.07%SOL$121.96▲ 4.05%TOTAL CRYPTO$2.89T▼ 2.28%S&P 5007,736.91▲ 0.78%NASDAQ27,056.07▲ 3.46%DOW51,776.48▼ 3.36%GOLD4,326.50▼ 7.84%WTI92.15▲ 11.89%BRENT97.25▲ 9.79%EUR/USD1.1403▼ 2.27%USD/JPY157.13▼ 1.27%DXY100.97▲ 2.08%
Crypto

Bitget Hack Grows to $387.5 Million, Fund Takes the Hit

Bitget raised its hack loss estimate to $387.5 million and pointed at North Korean hackers, while its protection fund could cover most of the bill.

Pexels – Lucas Andrade

Bitget raised its loss estimate from Thursday’s hack to $387.5 million, up from $351.6 million, after finding transfers through Zcash and TRON that the first count missed. The exchange says the attack pattern looks like the work of North Korean state-linked hackers, though it has not confirmed the attribution.

The breach came to light at 18:31 UTC on September 24, when Bitget’s monitoring systems flagged unauthorized transfers leaving some of its hot wallets. Within about an hour, on-chain investigators had tracked roughly $183 million in assets moving from wallets labeled as Bitget’s to a single freshly created address. The total kept climbing as investigators followed the money across at least five blockchains, and Bitget went public with a confirmed figure of $351.6 million hours later before revising it upward again on Friday.

How the attackers got in

CEO Gracy Chen explained the mechanism in a livestream and a series of posts on X. The attackers did not steal private keys and did not forge user withdrawal requests. Instead, they compromised a backend system inside Bitget’s wallet infrastructure and used it to spoof transaction data, tricking the exchange’s own authorization process into approving payouts that looked routine.

“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” Chen wrote. “Private key compromise has been ruled out.” She added that loss containment is confirmed and no further unauthorized transfers are possible, while the specific method of system intrusion remains under active investigation. A full technical report will follow once the company confirms its findings.

The breach reached both the hot wallet layer, the internet-connected reserve an exchange uses to process everyday withdrawals, and the warm wallet buffer that sits between hot wallets and offline cold storage. That buffer normally tops up hot wallets when balances run low and pulls excess deposits off the internet so too much capital is not left exposed. Bitget says its cold wallets, the offline vault, remain fully secure.

The single biggest piece of the haul is roughly 103 million XRP, worth about $157 million. Early on, a newly created wallet starting with 0xe410 swapped $19.67 million in USDT0, a cross-chain version of Tether’s dollar token, for 7,111 ETH in six minutes on Arbitrum. The order ran through UniswapX and 1inch Fusion at roughly 5% above market price, the kind of premium that shows up when speed matters more than getting a good price. Pseudonymous researcher DCF GOD first flagged the activity, and analysts at Bubblemaps and Arkham pieced together the pattern before Bitget confirmed anything.

The freeze that only freezes a slice

Circle blacklisted an address labeled “Bitget Exploiter 8” on Etherscan at 05:00 UTC Friday. The wallet held 218,023 USDT and 99,990 USDC, about $318,000 in total alongside 170.47 ETH, and blockchain security firm MistTrack confirmed Tether banned the same wallet. That is a small fraction of the haul. MistTrack’s tracker shows other exploiter addresses still holding more than 63,000 ETH, which no stablecoin issuer can touch because ether is a decentralized asset with no freeze function.

Circle moved faster this time than after April’s $285 million Drift hack, when an attacker pushed roughly $232 million in USDC from Solana to Ethereum through Circle’s own cross-chain transfer protocol and critics, including ZachXBT, said the issuer should have blacklisted wallets sooner. Circle said then, as it says now, that it freezes assets when legally required.

The fund math

Bitget’s User Protection Fund, set up in 2022, holds 5,500 BTC separate from the reserves backing customer balances. At the exchange’s stated valuation of more than $464 million, the revised loss figure equals about 83.5% of the fund. A full payout would leave roughly $76.5 million, below the $300 million commitment Bitget advertises. The fund averaged $382 million in August, ranging from $345.3 million to $441.5 million, so its dollar value moves with bitcoin’s price. The calculation remains hypothetical because frozen or recovered assets could reduce the amount ultimately drawn.

Chen said Bitget also holds more than $1 billion of its own assets, but the company has not said how any compensation would be split between the fund and its own balance sheet. Some stolen assets have been frozen through coordination with exchanges, blockchain foundations and security firms, and Bitget launched a recovery bounty paying 5% of assets frozen or recovered, excluding actions taken under court orders or law-enforcement processes.

What happens next

Mandiant and SlowMist are assisting with the investigation and security checks. Bitget says it has identified the attack path and remediated the underlying vulnerability. Deposits and trading stayed open throughout, but withdrawals remain frozen pending a security review. The exchange has committed to announcing the status and timing of restored withdrawals by 04:00 UTC on September 26, and Chen said the company will not commit to a recovery window it cannot guarantee.

Chen said IP addresses identified in the investigation match VPN choices used by “a certain DPRK group” and that the on-chain signatures line up with techniques tied to North Korean state-linked hacking groups. She stressed the attacker’s identity is unconfirmed and no technical evidence has been made public. Law enforcement is now involved, according to the company.

If the attribution holds, this would rank among the largest crypto thefts linked to Pyongyang, which analysts estimate has funded a meaningful share of its weapons program through stolen digital assets. It would also join a bruising year for exchange security: a Blockaid report counted $1.1 billion in losses across 212 incidents in the first half of 2026, with key compromises overtaking contract bugs as the leading cause. For Bitget, the immediate test is narrower, restoring withdrawals without a bank run and rebuilding a protection fund that one bad night nearly emptied.

SourcesCoinDesk; Decrypt; Finance Magnates; Benzinga
Share: X