Summary
- Bitget has reported a $387.5 million breach that occurred on September 24, where attackers mimicked transaction data to gain unauthorized approvals from hot and warm wallets, rather than accessing private keys.
- The breach included an estimated 103 million XRP, valued at $157 million.
- According to CEO Gracy Chen, the IP addresses and blockchain patterns observed correspond to methods used by North Korean state-affiliated hackers.
In what is anticipated to be the largest cryptocurrency hack of the year, Bitget has confirmed a theft amounting to approximately $387.5 million. North Korea is suspected to be behind the attack, although this has not yet been officially verified, and Bitget has stated that law enforcement is actively investigating.
The incident began when Bitget's security systems identified unauthorized transactions from some of its hot wallets at 18:31 UTC on September 24. Within an hour, on-chain analysts had already calculated about $183 million in stablecoins, Ethereum, and other cryptocurrencies being transferred out of wallets associated with the exchange.
By the time Bitget publicly acknowledged the breach hours later, the estimated losses had escalated to $351.6 million. The exchange, one of the largest in the sector, later revised this figure to $387.5 million.
In a livestream and a series of posts on X, CEO Gracy Chen detailed the breach, explaining that the attackers did not forge user withdrawal requests or obtain the cold wallet's private keys. Instead, they compromised a backend system within Bitget's wallet infrastructure, allowing them to spoof transaction data and deceive the exchange's authorization process into approving what appeared to be legitimate payouts.
In simpler terms, the hackers did not steal the vault's combination; they created convincing documentation that led the system to authorize the transactions without due diligence—analogous to presenting a forged withdrawal slip to a bank teller who checks the form but not the identity of the individual.
Blockchain analysts had begun piecing together the situation before Bitget made any announcements. A pseudonymous researcher known as DCF GOD highlighted a newly created wallet that spent $19.67 million in USDT0—a cross-chain variant of the dollar-pegged stablecoin Tether—to acquire 7,111 ETH in just six minutes, paying approximately 5% above the market rate via decentralized exchanges UniswapX and 1inch Fusion.
In less than 24 hours following the September 24 incident, we are continuing our investigation with Mandiant and SlowMist. A thorough forensic analysis takes more than a day, and we will share further findings as they become available. Three key…
— Gracy Chen @Bitget (@GracyBitget) September 25, 2026
Subsequent transactions involved additional wallets linked to Bitget, transferring assets across at least five different blockchains to addresses controlled by the attackers. The largest single asset taken was approximately 103 million XRP, valued at around $157 million.
Chen confirmed that the outflow has been halted, and no further unauthorized transfers can occur. She stated that Bitget's User Protection Fund, which has over $464 million, will fully cover the losses, ensuring that customer account balances remain unaffected despite the loss of funds.
Throughout the incident, deposits and trading continued as normal, with withdrawals temporarily suspended as a precaution.
Bitget established the protection fund years ago specifically to address potential scenarios like this, given the frequent occurrence of hacks in the industry. In 2023, the fund had a total of $300 million set aside to compensate for hacks and theft, ensuring users would not bear the losses.
Regarding the identity of the hackers, Chen has cautiously pointed to North Korea, noting that "we've identified some IP addresses that match the VPN selections made by a certain DPRK group," adding that "the pattern closely resembles previous actions by the North Korean team." She also mentioned that the on-chain signatures align with techniques linked to North Korean state-sponsored hacking groups, while emphasizing that the attacker's identity remains unverified and no technical evidence has been disclosed publicly.
Chen revealed that she has been personally targeted by the same group, having lost approximately $80,000 from a private wallet outside of Bitget. The Lazarus Group from North Korea, also known under the alias TraderTraitor, has been implicated in some of the biggest thefts in the cryptocurrency sector, including the $1.4 billion Bybit hack in February 2025, which the FBI confirmed weeks later was orchestrated by North Korea. According to blockchain analytics firm Chainalysis, the country's total haul from hacks in 2025 exceeded $2 billion.
Bitget has committed to providing a comprehensive report on the incident, including a root-cause analysis, once its technical teams complete their system remediation. Withdrawals will remain paused until tomorrow, when the exchange plans to announce a strategy for those wishing to resume withdrawals.
