Crypto exchange Bitget reported a major security breach resulting in the unauthorized transfer of approximately $351.6 million in digital assets. The company suspects North Korean hackers are responsible, citing preliminary evidence from an ongoing investigation. Bitget CEO Gracy Chen stated that investigators identified internet protocol addresses linked to VPN services previously used by a North Korean hacking group, and the attack pattern resembled earlier operations attributed to North Korea. The specific method of intrusion is still under technical investigation, but private key compromise has been ruled out [1].
The breach involved 19 transfers from Bitget's hot and warm wallet infrastructure, while cold wallets remained secure. Affected assets included ether, XRP, USDT, USDC, Avalanche, and BNB, spanning the Ethereum, XRP Ledger, Avalanche, BNB Smart Chain, and Arbitrum networks. Initial on-chain estimates suggested outflows of about $183 million, but Bitget clarified that these analyses did not capture activity across all affected blockchains, confirming the total loss at $351.6 million [1].
Bitget's security team determined that the attacker breached a critical backend wallet system, spoofed transfer information, and triggered the exchange's authorization-signing process. The breach has been contained, preventing further unauthorized outflows. Withdrawals are currently suspended as technical teams work to repair and reinforce the affected systems, though deposits and trading continue as normal. Chen indicated that withdrawals could resume within hours or days, but not weeks. The company asserts that customer balances remain accurate and that the loss is fully covered by its User Protection Fund, which holds over $464 million [1].
Bybit CEO Ben Zhou expressed support for Bitget, noting that Bybit is updating its LazarusBounty platform to help trace the stolen funds. Zhou also referenced Bitget's previous assistance to Bybit following its own $1.5 billion hack in February 2025 [1].
CONCLUSION
Bitget has suffered a significant security breach, with $351.6 million in digital assets stolen in an attack suspected to be linked to North Korean hackers. The exchange has contained the breach, suspended withdrawals, and assured users that losses are covered by its protection fund. The incident underscores ongoing security risks in the crypto sector and has prompted industry collaboration to trace the stolen funds.
