Home Cybersecurity & Hacking Bitget Resumes Bitcoin Withdrawals After North Korean Hackers Steal Nearly $400 Million in Massive Cyber Heist

Bitget Resumes Bitcoin Withdrawals After North Korean Hackers Steal Nearly $400 Million in Massive Cyber Heist

by admin

Cryptocurrency exchange Bitget has officially resumed Bitcoin withdrawals following a temporary, platform-wide freeze enacted last week. The suspension was triggered by a sophisticated security breach that resulted in the theft of hundreds of millions of dollars in digital assets. According to internal investigations and on-chain analytics, the devastating cyber attack has been attributed to state-sponsored hackers operating out of North Korea.

The exchange confirmed that the specific security vulnerability exploited during the breach has been successfully patched and secured. While Bitcoin withdrawals are once again operational, Bitget management has laid out a phased restoration schedule for other supported assets, networks, and fiat channels to ensure systemic stability and safety.

Phased Withdrawal Restoration Schedule

To prevent network congestion and maintain rigorous security oversight, Bitget has instituted a staggered timeline for bringing its remaining withdrawal functions back online.

According to the exchange’s official roadmap, withdrawal services will return in distinct waves:

  • Bitcoin (BTC): Resumed immediately following the initial security patch.
  • Ethereum and Layer-2 Networks (ETH via Ethereum, BSC, Arbitrum, Base, and Optimism): Scheduled to resume on September 29 at 8:00 UTC.
  • Tether and Major Stablecoins (USDT via Ethereum, BSC, Solana, and Tron): Scheduled to resume on September 30 at 8:00 UTC.
  • Remaining Tokens, Fiat, and P2P Assets: Scheduled to open progressively starting October 2 at 8:00 UTC.

Throughout the disruption, Bitget has maintained that trading and deposit functionalities remained fully operational. Executives have repeatedly emphasized that the withdrawal pause was strictly a precautionary defense mechanism rather than a reflection of liquidity insolvency or asset depletion.

"The temporary withdrawal pause remains a security measure and is not related to the availability of user assets. User account balances remain unaffected, and Bitget’s Protection Fund covers the financial impact of this platform-wide incident," the company stated in a public announcement. Furthermore, leadership confirmed that the threat has been entirely contained, ensuring that no further unauthorized transfers can take place.

Chronology of the Breach

The unfolding crisis began late last week when automated security monitoring systems at Bitget detected anomalous transactional behavior. Security teams flagged multiple unauthorized transfers originating from a limited number of the exchange’s hot and warm wallets.

Upon deeper inspection, engineers discovered that malicious actors had successfully breached a critical backend system nested within Bitget’s proprietary wallet infrastructure. By infiltrating this subsystem, the attackers managed to spoof transaction data, effectively tricking the exchange’s automated authorization protocols into approving outbound transfers to external, attacker-controlled addresses.

By Thursday, the scale of the breach became evident, forcing Bitget executives to pull the emergency brake. All withdrawal operations were immediately suspended to stanch the flow of capital out of the ecosystem. Initial estimates placed the losses at roughly $350 million.

However, as blockchain forensics teams conducted more comprehensive tracing, the estimated financial damage was revised upward. On Friday, updated figures released by Bitget—backed by on-chain tracking and transaction classification data—revealed that the final sum stolen in the multi-chain assault totaled an astounding $387.5 million.

Bitget CEO Gracy Chen provided further technical color on the attack, noting that the multi-pronged exploit targeted multiple blockchains, including Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, Binance Smart Chain (BSC), and Base. A wide variety of digital assets were siphoned during the raid, prominently featuring ETH, XRP, BNB, AVAX, USDT, and USDC.

Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist

Attribution to North Korean State-Sponsored Actors

Through intensive on-chain analysis, IP behavior profiling, and tactical tracking, Bitget leadership and independent cybersecurity researchers swiftly pointed the finger at North Korea. The sophisticated nature of the exploit—characterized by deep backend infrastructure compromise and precise transactional spoofing—bears the classic hallmarks of advanced persistent threat (APT) groups hailing from the hermetic nation.

Prominent state-backed cyber-espionage and financial theft units from North Korea, most notably the Lazarus Group and related syndicates, have built a formidable reputation over the past decade for targeting the global cryptocurrency industry. These operations are frequently utilized by the regime to launder money and bypass heavy international economic sanctions, funding state priorities through targeted cyber warfare.

The Bitget incident is merely the latest in a long, troubling lineage of massive cryptocurrency heists linked to Pyongyang. The scale of these operations has expanded dramatically over recent years. For instance, the cybersecurity community is still reeling from the historic Bybit exploit, which saw malicious actors walk away with an unprecedented $1.5 billion from an Ethereum cold wallet—securing its place as the largest crypto theft recorded in history.

Data compiled by blockchain analytics firm Elliptic in February 2025 underscores the staggering scope of these state-sponsored campaigns. According to Elliptic’s estimates, North Korean threat groups have successfully plundered more than $6 billion in cumulative cryptocurrency assets since 2017.

Mitigation, Recovery Efforts, and Bounty Programs

In the wake of the disaster, Bitget has moved aggressively to mitigate customer losses and track down the stolen funds. The exchange has repeatedly reassured its user base that individual account balances are completely safe and insulated from the corporate loss. Management has reiterated that Bitget’s heavily capitalized Protection Fund will absorb the financial impact of the platform-wide breach, preventing any direct socialization of losses onto everyday traders.

To incentivize the crypto community and decentralized finance (DeFi) investigators to aid in the recovery, Bitget launched an official Recovery Bounty Program. Under this initiative, the exchange is offering a generous 5% bounty reward to individuals, security researchers, or white-hat hackers who provide actionable intelligence that leads to the successful freezing or recovery of the stolen capital.

Additionally, Bitget has actively collaborated with centralized exchanges, decentralized finance protocols, and major blockchain analytics firms to blacklist addresses linked to the attackers. By blacklisting these wallets, the exchange aims to make it exceedingly difficult for the hackers to launder or cash out the stolen tokens through legitimate liquidity pools or fiat off-ramps.

Broader Implications for Centralized Crypto Exchanges

The Bitget breach serves as a stark reminder of the persistent and evolving cybersecurity threats facing centralized cryptocurrency exchanges (CEXs) worldwide. Despite substantial investments in multi-signature architecture, hardware security modules, and real-time anomaly detection, exchanges remain prime targets for state-sponsored threat actors wielding nation-state resources.

Industry analysts point out that as perimeter security surrounding cold storage solutions continues to harden, attackers are increasingly shifting their focus toward complex backend infrastructure, third-party vendor integrations, and internal authorization pipelines. By compromising these auxiliary systems, hackers can manipulate transactional validation frameworks from the inside, bypassing standard withdrawal limits and manual review triggers.

The incident is expected to prompt a sweeping audit across the centralized exchange sector. Security posture reviews will likely focus heavily on backend wallet management systems, API keys, administrative access controls, and multi-factor authorization workflows.

Furthermore, regulatory bodies and compliance watchdogs are likely to scrutinize how exchanges handle emergency liquidity crises, reserve proofs, and incident transparency. Bitget’s swift communication, albeit disruptive to users, has been viewed by some market observers as a necessary containment playbook, though the long-term reputational and financial fallout remains to be seen.

As Bitget works through its phased withdrawal schedule over the coming days, the cryptocurrency market will be watching closely to ensure that user funds are successfully returned without further technical hitches. Meanwhile, international law enforcement and blockchain intelligence agencies continue their pursuit of the stolen funds, though recovering assets from sophisticated state-sponsored syndicates remains an exceptionally difficult uphill battle.

You may also like

Leave a Comment