Major cryptocurrency exchange Bitget has confirmed a devastating security breach resulting in the theft of approximately $351.6 million from its hot and warm wallets. The incident, which unfolded on Thursday evening, has sent shockwaves through the digital asset ecosystem, once again casting a harsh spotlight on the vulnerabilities plaguing centralized crypto platforms and the persistent threat posed by state-sponsored cybercriminal syndicates.
According to official disclosures from the exchange and statements provided by Bitget CEO Gracy Chen, preliminary forensic assessments strongly link the sophisticated intrusion to North Korean advanced persistent threat (APT) groups. The attackers successfully compromised a critical backend wallet-service system, allowing them to manipulate transaction metadata and trigger unauthorized authorization-signing processes across multiple blockchain networks.
Despite the staggering financial loss, Bitget leadership has emphasized that the platform’s cold storage infrastructure—which houses the overwhelming majority of user assets—remains entirely secure and untouched. Furthermore, the exchange’s independent self-custodial product, the Bitget Wallet, was isolated from the attack vector and experienced zero disruption. To mitigate panic and reassure the user base, executives confirmed that the company’s robust User Protection Fund, which currently boasts a reserve of over $464 million in Bitcoin, will fully cover all stolen funds. Customer account balances remain accurate, and while withdrawals were temporarily halted as a precautionary containment measure, trading and deposits have continued to operate normally.
Chronology of the Breach and Immediate Response
The timeline of the incident highlights a rapid detection by automated security monitoring mechanisms, followed by an aggressive, multi-layered containment strategy executed in collaboration with global cybersecurity heavyweights.
Thursday evening marked the critical turning point when Bitget’s internal security operations center flagged anomalous outbound transactions originating from a restricted cohort of hot and warm wallets. Realizing that unauthorized transfers were actively draining funds, exchange engineers initiated emergency protocols.
By Friday morning, Bitget had temporarily suspended all platform withdrawals to halt the bleeding and prevent further asset exfiltration. Simultaneously, the exchange mobilized an elite incident response coalition, partnering with prominent on-chain security institutions, law enforcement agencies, and premier cybersecurity firms Mandiant and SlowMist.
By analyzing IP behavior patterns, transaction signatures, and routing methodologies, investigators quickly drew parallels to the tactics, techniques, and procedures (TTPs) historically employed by North Korean hacking organizations. Swift coordination with blockchain protocols and validator nodes across the affected networks resulted in the immediate freezing of several hacker-controlled wallet addresses, effectively locking a portion of the stolen capital before it could be laundered through privacy mixers or decentralized finance (DeFi) protocols.
Scope of the Attack and Affected Assets
The breach was not limited to a single blockchain ecosystem, highlighting the operational complexity and multi-chain capabilities of the threat actors. According to details shared by CEO Gracy Chen, the exploit spanned at least seven distinct major blockchain networks.
The targeted chains included:
- Ethereum (ETH)
- XRP Ledger (XRP)
- Arbitrum
- Avalanche (AVAX)
- Optimism
- Binance Smart Chain (BSC)
- Base
A diverse basket of digital assets was compromised during the assault. While single-chain losses were most heavily concentrated in XRP on the XRP Ledger, the attackers also siphoned substantial quantities of Ether (ETH), Binance Coin (BNB), Avalanche (AVAX), Tether (USDT), USD Coin (USDC), and various other altcoin tokens.
In her public statements, CEO Gracy Chen elaborated on the mechanics of the intrusion. "The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out," Chen explained. "No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation."

Bitget has committed to maintaining transparent communication with its global user base. Executives have reiterated that normal operations—including the resumption of withdrawals—will be systematically restored as soon as external forensic investigators and internal security teams officially confirm that the environment is thoroughly sanitized and safe.
The Financial Safety Net: Bitget’s User Protection Fund
In the wake of major exchange hacks, user trust is frequently decimated by insolvency fears and prolonged withdrawal freezes. To counter this, modern crypto exchanges have increasingly relied on dedicated insurance reserves, often styled as user protection funds.
Bitget’s response to the $351.6 million heist serves as a stress test for its own financial safety net. The Bitget User Protection Fund, which currently holds 5,500 BTC valued at approximately $464 million, exceeds the total value of the stolen assets. Because this fund is held in reserve specifically for catastrophic scenarios, the exchange is uniquely positioned to absorb the blow without passing losses onto individual account holders.
Industry analysts have noted that while the presence of the User Protection Fund prevents immediate systemic insolvency for Bitget, the psychological toll on retail investors and the reputational damage to the platform’s security architecture will require sustained remediation efforts. Transparency regarding the exact vulnerability in the backend wallet-service system will be paramount for restoring absolute confidence among institutional and retail clients alike.
The Shadow of State-Sponsored Cybercrime: North Korea’s Crypto Arsenal
The attribution of the Bitget heist to North Korean state-sponsored hackers places the event within a well-documented, highly alarming macroeconomic trend. Over the past decade, Pyongyang-linked hacking collectives—most notably groups like the Lazarus Group and related sub-units—have evolved from traditional bank robberies into highly specialized, hyper-efficient cryptocurrency cyber-armies.
Intelligence agencies and blockchain analytics firms have repeatedly warned that state-backed cyber operations in North Korea are explicitly designed to bypass international economic sanctions and generate revenue for the regime’s heavily sanctioned weapons programs, including its ballistic missile development initiatives.
The scale of these operations is staggering. According to comprehensive data published by blockchain intelligence firm Chainalysis, state-backed North Korean hacking syndicates amassed an estimated $1.34 billion across 47 distinct cryptocurrency heists over the course of a single calendar year. Furthermore, digital asset intelligence firm Elliptic reported that North Korean threat actors have collectively stolen upwards of $6 billion in cryptocurrency assets since 2017.
The Bitget incident also follows closely on the heels of other historic cyber attacks targeting the centralized exchange ecosystem. Most notably, the digital asset community is still reeling from the unprecedented Bybit hack, in which North Korean operatives successfully penetrated an Ethereum cold wallet to steal a staggering $1.5 billion—marking the largest recorded crypto heist in financial history.
Broader Implications for Centralized Crypto Exchanges
The Bitget breach underscores enduring vulnerabilities within the centralized exchange (CEX) model. While platforms invest heavily in cold storage solutions—offline cryptographic vaults that are virtually immune to remote network intrusions—operational hot and warm wallets remain necessary to facilitate day-to-day liquidity, instant trading, and user withdrawals. These active operational systems inherently require network connectivity, presenting a persistent attack surface for sophisticated adversaries.
Security experts emphasize that as perimeter defenses around cold storage improve, advanced threat actors are increasingly shifting their focus toward backend infrastructure, third-party service providers, API gateways, and authorization-signing workflows. By compromising the administrative or backend systems that govern hot wallet transactions, attackers can trick internal authorization protocols into executing fraudulent transfers under the guise of legitimate administrative operations.
For the broader fintech and cryptocurrency sectors, the Bitget incident serves as an urgent reminder of the necessity for Zero Trust architecture, rigorous internal segmentation, multi-party computation (MPC) key management, and continuous behavioral anomaly detection. As long as centralized platforms hold billions of dollars in liquid digital assets, they will remain primary targets for sophisticated, well-funded nation-state actors.
As the global investigation into the Bitget breach continues, regulatory bodies, cybersecurity firms, and exchange operators will be watching closely to see how quickly the platform can safely resume normal withdrawal operations and whether international law enforcement can successfully track, freeze, and recover the remaining unrecovered funds from the sprawling multi-chain exploit.







