Bitget confirmed the breach after its security systems flagged unauthorized transfers from a limited number of hot wallets at 18:31 UTC on Thursday. The exchange immediately activated emergency response protocols and suspended all withdrawals, stating that cold wallets and the vast majority of platform assets remained secure.
In a detailed post on X, Chen explained that the attackers had “compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out.” She added that no further unauthorized transfers were possible and that the specific method of system intrusion remained under investigation.
Chen also said the exchange did not believe the incident was an inside job. She noted that investigators had identified IP addresses matching VPN choices associated with a Democratic People’s Republic of Korea (DPRK) hacking group, saying, “Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations.”
The incident affected multiple blockchain networks, including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. Assets stolen include ETH, XRP (the largest single-chain loss), BNB, AVAX, USDT, USDC, and other tokens. Some chains have frozen the hacker wallet addresses since the attack.
Bitget said its self-custodial Bitget Wallet was not affected, as it operates on independent infrastructure. The exchange’s User Protection Fund, which currently holds more than $464 million in Bitcoin, will cover all losses. Customer account balances remain accurate, and deposits and trading continue normally. Withdrawals will be restored once investigators confirm it is safe to resume operations.
North Korean hackers have been linked to several major crypto thefts, including the $1.5 billion Bybit heist earlier this year.