Bitget Loses $351.6 Million in Hot-Wallet Breach, Suspends Withdrawals
The Bitget breach led to unauthorized transfers from a limited number of hot wallets and a reported $351.6 million loss across parts of the exchange’s wallet infrastructure, prompting a suspension of withdrawals and a security review while deposits and trading continued to operate normally.
Key Points
- Unauthorized transfers were detected at 18:31 UTC on September 24, 2026, and emergency response protocols were activated within minutes.
- The incident affected hot wallets and several assets, while cold wallets and the overwhelming majority of platform assets remained secure and unaffected.
- Bitget Wallet was not affected, and third-party investigators including Google-owned Mandiant and SlowMist were brought in.
- Bitget said the attack method was highly consistent with known patterns of North Korean hacker organizations, that North Korean involvement was very likely while investigators continued examining the evidence, and that it had contacted the foundations of all affected chains; some foundations confirmed freezing hacker wallet addresses.
At 18:31 UTC on September 24, 2026, security systems identified unauthorized transfers involving a limited number of hot wallets. Withdrawals were suspended while a comprehensive security review continued, and deposits and trading remained available. No CVE identifiers or named software vulnerabilities were disclosed.
“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation.” – Bitget
The compromise did not involve stolen private keys. Bitget Wallet operates as a self-custodial wallet on a completely separate and independent infrastructure from Bitget Exchange and was not affected by the incident.
“Bitget Wallet operates as a self-custodial wallet on a completely separate and independent infrastructure from Bitget Exchange and was not affected by this incident.” – Bitget
The affected assets listed by Bitget were ETH, XRP, BNB, AVAX, USDT and USDC, with chains including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base. Bitget also said its User Protection Fund holds more than $464 million and covers the entire loss.
Based on IP behavior patterns and on-chain analysis, the attack method was described as highly consistent with known patterns of North Korean hacker organizations. The company characterized North Korean involvement as very likely while investigators continued examining the evidence, and it said it had contacted the foundations of all affected chains; some foundations had confirmed freezing hacker wallet addresses.
“Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations.” – Bitget
Bitget said services would resume once the investigation was complete.
Sources