Back to News

Bitget Loses $351.6 Million in Hot-Wallet Breach, Suspends Withdrawals

Bitget Loses $351.6 Million in Hot-Wallet Breach, Suspends Withdrawals

The Bitget breach led to unauthorized transfers from a limited number of hot wallets and a reported $351.6 million loss across parts of the exchange’s wallet infrastructure, prompting a suspension of withdrawals and a security review while deposits and trading continued to operate normally.

Key Points

  • Unauthorized transfers were detected at 18:31 UTC on September 24, 2026, and emergency response protocols were activated within minutes.
  • The incident affected hot wallets and several assets, while cold wallets and the overwhelming majority of platform assets remained secure and unaffected.
  • Bitget Wallet was not affected, and third-party investigators including Google-owned Mandiant and SlowMist were brought in.
  • Bitget said the attack method was highly consistent with known patterns of North Korean hacker organizations, that North Korean involvement was very likely while investigators continued examining the evidence, and that it had contacted the foundations of all affected chains; some foundations confirmed freezing hacker wallet addresses.

At 18:31 UTC on September 24, 2026, security systems identified unauthorized transfers involving a limited number of hot wallets. Withdrawals were suspended while a comprehensive security review continued, and deposits and trading remained available. No CVE identifiers or named software vulnerabilities were disclosed.

“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation.” – Bitget

The compromise did not involve stolen private keys. Bitget Wallet operates as a self-custodial wallet on a completely separate and independent infrastructure from Bitget Exchange and was not affected by the incident.

“Bitget Wallet operates as a self-custodial wallet on a completely separate and independent infrastructure from Bitget Exchange and was not affected by this incident.” – Bitget

The affected assets listed by Bitget were ETH, XRP, BNB, AVAX, USDT and USDC, with chains including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base. Bitget also said its User Protection Fund holds more than $464 million and covers the entire loss.

Based on IP behavior patterns and on-chain analysis, the attack method was described as highly consistent with known patterns of North Korean hacker organizations. The company characterized North Korean involvement as very likely while investigators continued examining the evidence, and it said it had contacted the foundations of all affected chains; some foundations had confirmed freezing hacker wallet addresses.

“Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations.” – Bitget

Bitget said services would resume once the investigation was complete.

Sources

Mayank Mehra

Written by

Mayank Mehra

Mayank Mehra is a cybersecurity professional with 8+ years of hands-on experience in application security, penetration testing, and AI Security. He holds industry-recognised certifications including CEH, CAPEN, and CRTP, and has worked across vulnerability assessments, penetration testing and securing AI-powered systems.

View all posts →