Bitget says $351.6M hack used spoofed transfers, suspects North Korean involvement

CEO Gracy Chen says attackers compromised a wallet backend system to forge transaction data; withdrawals remain suspended as investigation continues

By LineZotpaper
Published
Updated
Read Time2 min
Sources5 outlets
Crypto exchange Bitget has disclosed that the $351.6 million theft on Thursday involved attackers compromising a wallet backend system to spoof transaction data — not stolen private keys — and that preliminary IP analysis points to a North Korean hacking group. Chief executive Gracy Chen announced the findings during a live Q&A on X, while the exchange continues to work with law enforcement and cybersecurity firms Mandiant and SlowMist.

Bitget confirmed the breach after its security systems flagged unauthorized transfers from a limited number of hot wallets at 18:31 UTC on Thursday. The exchange immediately activated emergency response protocols and suspended all withdrawals, stating that cold wallets and the vast majority of platform assets remained secure.

In a detailed post on X, Chen explained that the attackers had “compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out.” She added that no further unauthorized transfers were possible and that the specific method of system intrusion remained under investigation.

Chen also said the exchange did not believe the incident was an inside job. She noted that investigators had identified IP addresses matching VPN choices associated with a Democratic People’s Republic of Korea (DPRK) hacking group, saying, “Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations.”

The incident affected multiple blockchain networks, including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. Assets stolen include ETH, XRP (the largest single-chain loss), BNB, AVAX, USDT, USDC, and other tokens. Some chains have frozen the hacker wallet addresses since the attack.

Bitget said its self-custodial Bitget Wallet was not affected, as it operates on independent infrastructure. The exchange’s User Protection Fund, which currently holds more than $464 million in Bitcoin, will cover all losses. Customer account balances remain accurate, and deposits and trading continue normally. Withdrawals will be restored once investigators confirm it is safe to resume operations.

North Korean hackers have been linked to several major crypto thefts, including the $1.5 billion Bybit heist earlier this year.

§

Analysis

Why This Matters

  • The breach is one of the largest crypto exchange hacks of 2026, raising fresh concerns about the security of centralized exchange hot wallets.
  • Bitget's use of a User Protection Fund to cover losses may reassure users in the short term, but the suspension of withdrawals underscores the operational disruption such incidents cause.
  • Attribution to North Korean state-linked hackers, if confirmed, would add to a growing pattern of DPRK-backed crypto heists used to fund weapons programs.

Background

Crypto exchanges have long been prime targets for hackers, with billions of dollars stolen from platforms such as Mt. Gox, Coincheck, and more recently Bybit. Bitget is a Seychelles-registered exchange that has grown rapidly in recent years, offering spot and derivatives trading. The hack comes despite the industry’s increased investment in security infrastructure and insurance funds.

Key Perspectives

Bitget: The exchange emphasizes that customer funds are protected by a $464 million buffer fund and that the breach was limited to a small number of hot wallets. It is cooperating with law enforcement and security partners. Affected Users: While Bitget guarantees reimbursement, the temporary withdrawal freeze creates uncertainty. Some users may question the exchange’s security protocols and whether hot wallet holdings were adequately protected. Security Researchers: Firms like Mandiant and SlowMist are investigating the attack vector, which involved spoofed transaction data — a method that exploits backend signing processes rather than individual private keys. This technique underscores the need for multi-layered authentication for wallet systems.

What to Watch

  • The speed of withdrawal restoration — a prolonged freeze could erode user trust.
  • Official attribution by U.S. or South Korean authorities, which would have geopolitical implications.
  • Whether any of the stolen funds are recovered through blockchain tracking and frozen addresses.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.