Bitget Loses 351.6 Million Dollars in Hot Wallet Breach. Its Protection Fund Holds 5,500 BTC.
Bitcoin was not among the stolen assets. Whether the exchange sells any of the fund's bitcoin is still open.
The cryptocurrency exchange Bitget detected unauthorized transfers from several of its hot wallets on September 24 at 18:31 UTC. According to the company, assets worth about 351.6 million dollars left its wallets before emergency procedures took effect within minutes. Bitget suspended withdrawals, kept deposits and trading open, and says customer balances remain fully covered. Its CEO, Gracy Chen, said a group linked to North Korea is very likely behind the attack.
What was taken
The first on-chain alerts on Thursday evening put the figure at about 183 million dollars, drained within an hour. The total roughly doubled once the XRP outflows were counted. Lookonchain's tally of the exploiter addresses lists:
- 102.93 million XRP, worth about 157.5 million dollars
- 31,890 ETH, worth about 85.8 million dollars
- 34.75 million dollars in USDT, 19.67 million dollars in USDT0 and 21.05 million dollars in USDC
- smaller positions in BNB, AVAX, TRX and XAUt, a token backed by physical gold
The transfers ran across at least seven networks, among them Ethereum, the XRP Ledger, Arbitrum and Base. No bitcoin appears in any of the published tallies.
The attacker started converting the proceeds almost immediately. One freshly created wallet bought 7,111 ETH on Arbitrum with the 19.67 million dollars in USDT0 within six minutes, paying up to 5 percent above the spot price. After most of the assets on EVM networks had been swapped, Lookonchain counted about 67,982 ETH, worth roughly 183 million dollars, in exploiter addresses.
How the attackers got in
Bitget separates its funds into hot, warm and cold wallets. The company says the breach reached part of the hot and warm layers and that its cold wallets were not affected.
According to Chen, no private keys were stolen. The attackers "compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out." The signing systems approved the transfers because the data they received looked like legitimate withdrawal requests. Because the attack happened upstream of the keys, it could reach several assets on several networks at once.
Bitget says the exact intrusion method is still under investigation and that a full technical report will follow. The security firms Mandiant and SlowMist are working on the case, and law enforcement has been notified.
Who may be behind it
Bitget's statement says the attack method is "highly consistent with known patterns of North Korean hacker organizations," based on IP behavior and on-chain analysis. In comments published on X, Chen said the team found IP addresses whose VPN usage patterns matched those of a specific group linked to North Korea, which in her words makes a North Korean connection "very likely."
The attribution is Bitget's own and preliminary. No government agency has confirmed it so far. North Korean groups have been behind several of the largest thefts in the industry. The FBI attributed the theft of about 1.5 billion dollars from the exchange Bybit in February 2025, the largest on record, to North Korea.
How Bitget says it will cover the loss
Bitget says customers will not carry the loss. "User funds are safe," the company wrote, adding that the full amount "falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million."
The fund holds 5,500 BTC, and its wallet addresses are public. On Friday, Bitget said the loss would be covered by the fund "after assessment" and that it would replenish the fund, with details to follow in a separate announcement. Chen also pointed to more than 1 billion dollars in proprietary assets beyond the fund and said customer funds remain backed one to one.
Measured against the fund, the loss is large. At the value Bitget cites, 351.6 million dollars equals about 76 percent of the fund. At a bitcoin price of about 83,900 dollars, it corresponds to roughly 4,190 BTC.
Part of the loss may still be recovered. On Friday, Circle and Tether blacklisted an exploiter address holding 218,023 USDT and 99,990 USDC, about 318,000 dollars or 0.09 percent of the total, according to CoinDesk, citing the tracking firm MistTrack. The same report notes that other exploiter addresses still hold more than 63,000 ETH, which no issuer can freeze. In a livestream, Chen said some of the affected funds "may have a chance of being recovered," without naming an amount.
Why the fund's bitcoin matters
The stolen assets were XRP, ether and stablecoins. The fund that is meant to cover them holds bitcoin. That mismatch has raised the question of whether Bitget will sell bitcoin to restore its balances in the affected assets.
Bitget has not said. Its statements so far commit to covering the loss and to replenishing the fund, not to a specific method. The exchange can draw on the fund, on its own assets or on both, and any recovered funds reduce the gap. Until Bitget publishes how it settles the loss, a sale of the fund's bitcoin is a possibility, not an announced step. Because the fund's addresses are public, any movement from them would be visible on-chain.
The bitcoin price barely moved on the news. Bitcoin traded at about 84,400 dollars on Thursday evening and at about 83,900 dollars on Friday, up 0.34 percent on the day. Bitget's own exchange token, BGB, fell about 3.2 percent.
What the incident shows about exchange custody
A balance on an exchange is a claim on the exchange, not bitcoin under the customer's control. Bitget's customers are not expected to lose money here because the company says it can absorb the loss. They never held the keys to the stolen coins, though. The keys, the signing systems and the backend that fed them were all Bitget's. This is the distinction behind the phrase "not your keys, not your coins," which our guide to self-custody puts into practice. Hot wallets exist because an exchange has to pay out quickly, and that constant connectivity is what makes them the exposed layer, as our comparison of hot and cold wallets explains.
Self-custody moves the risk rather than removing it. The thefts traced to a Coldcard entropy flaw showed that a signing device can fail its owner as well. The incident also shows both sides of stablecoins. An issuer can freeze tokens at an address, which helps a hacked exchange and is the same control that our analysis of the GENIUS Act describes as the built-in stop of a programmable dollar. At the protocol level, no party can freeze bitcoin.
What is still open
- Withdrawals: Chen said Bitget will reopen them only once security is confirmed and would not commit to a date.
- The technical report on how the attackers reached the backend system.
- The separate announcement on how the loss is settled and how the fund is replenished.
- Attribution beyond Bitget's own assessment.
Frequently Asked Questions
According to the on-chain tallies published so far, no. The stolen assets were mainly XRP, ether and the stablecoins USDT and USDC, plus smaller amounts of BNB, AVAX, TRX and a gold-backed token.
Bitget says no. It states that customer balances are accurate and that the full loss falls within its User Protection Fund, which holds 5,500 BTC worth more than 464 million dollars. Withdrawals remain suspended, and the exchange has not given a date for reopening them.
Bitget has not said. It has committed to covering the loss after assessment and to replenishing the fund, and it reports more than 1 billion dollars in proprietary assets beyond the fund. The fund's wallet addresses are public, so any sale from them would be visible on-chain.
Sources
- 1.Bitget — Statement on the hot wallet security incident, post on X, September 25, 2026
- 2.Lookonchain — Bitget was hacked for about $351.6M, post on X, September 25, 2026
- 3.Wu Blockchain — Bitget CEO: $350M hack very likely linked to North Korea, post on X, September 25, 2026
- 4.CoinDesk — Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gracy Chen says
- 5.BleepingComputer — Hackers steal $351.6 million in Bitget crypto exchange hack
- 6.Bitcoin.com News — Everything we know about Bitget's massive $351M hack
- 7.Decrypt — Bitget hacked as $350 million vanishes from crypto exchange wallets
- 8.ChainCatcher — Bitget: The protection fund holds 5,500 BTC
- 9.ChainCatcher — Bitget CEO: The platform was attacked not through key leakage
- 10.ChainCatcher — Bitget CEO: Some of the stolen funds may be recovered
- 11.CryptoSlate — Bitget's North Korea-linked $352 million hack could drain 76% of its protection fund
- 12.CoinDesk — Circle and Tether step in to freeze hacker wallet after massive Bitget crypto heist
- 13.Bitget — User Protection Fund
- 14.FBI — North Korea Responsible for $1.5 Billion Bybit Hack, public service announcement, February 26, 2025
Not financial advice. CanoeBit publishes educational content only. Nothing here is a recommendation to buy, sell, or hold any asset.