
Bitget loses $351.6M in hot wallet attack
Crypto exchange Bitget says suspected North Korean hackers stole $351.6 million from hot and warm wallets, and it has paused withdrawals while investigating.
On September 25, 2026, as reported by BleepingComputer, cryptocurrency exchange Bitget disclosed that a hack of its hot and warm wallets led to the theft of about $351.6 million. Hot and warm wallets are online-connected storage used to process customer deposits and withdrawals quickly, while cold wallets are kept offline for longer-term storage. Bitget said its security systems flagged multiple unauthorized transfers from a limited number of wallets on Thursday evening.
Bitget immediately suspended all withdrawals while investigating with help from law enforcement agencies, on-chain security institutions, and cybersecurity experts at Mandiant and SlowMist. The exchange said its separate self-custodial Bitget Wallet, which runs on independent infrastructure and where users hold their own private keys, was not affected. The company added that its User Protection Fund, which currently holds 5,500 BTC worth about $464 million, will cover all losses. In its statement, Bitget said approximately $351.6 million in assets were affected, but its cold wallets and the overwhelming majority of platform assets remain secure and unaffected. Customer account balances remain accurate, and deposits and trading continue to operate normally.
The company has not yet shared full details on how the attackers accessed its key backend wallet-service system, the internal software that manages wallet operations and authorizes transfers. Bitget said the intruders used that access to forge, or spoof, transaction data and then trigger the authorization-signing process that approves movement of funds. CEO Gracy Chen said the incident involved the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base chains, and affected multiple assets including ETH, XRP, BNB, AVAX, USDT, USDC, and other tokens. She added that the single-chain loss for XRP is the largest among them.
Chen also said some chains have confirmed that hacker wallet addresses were frozen after the attack, and she linked the theft to North Korean hackers. Based on IP behavior patterns and on-chain analysis, which is the inspection of public blockchain records, the attack method is highly consistent with known patterns of North Korean hacker organizations, she explained. Bitget has reported the matter to relevant institutions and is fully cooperating in a global investigation. The attacker compromised a critical backend system within the wallet infrastructure, used it to spoof transaction data, and triggered the authorization process to move funds out. No further unauthorized transfers are possible, but the specific method of system intrusion remains under active investigation. The company also said it will restore withdrawals as soon as possible after investigators confirm it is safe to resume normal operations.
North Korean threat groups have previously been linked to many major crypto theft incidents, including the Bybit hack, in which attackers stole $1.5 billion from the exchange's ETH cold wallet, the largest crypto heist ever recorded. Blockchain analysis company Chainalysis said two years ago that state-backed North Korean hacking groups stole $1.34 billion in 47 crypto heists throughout 2024. Elliptic estimated in February 2025 that North Korean hackers have stolen over $6 billion in crypto assets since 2017, with the proceeds reportedly spent on the country's ballistic missile program.
For website owners and businesses that run online services, a breach of this scale shows why independent review of backend infrastructure matters. AEU-I provides security-first IT, infrastructure and consulting that can help organizations audit and harden the systems behind their own customer-facing platforms, using only real, verifiable practices. While the Bitget incident is specific to a crypto exchange, the underlying lesson is the same for any business: an attacker who reaches the internal service that signs off on transactions can move assets even if the public-facing front end looks normal.
How to Protect Yourself
- If you use Bitget, visit the official website or app to check for the latest withdrawal status and your balance, and ignore messages that ask you to move funds immediately.
- Move long-term cryptocurrency into a private wallet you control, ideally an offline hardware wallet, and never share its recovery phrase with anyone.
- Turn on two-factor authentication for any exchange account and use an authenticator app rather than SMS codes.
- Be alert for phishing emails or fake support chats that mention the Bitget hack, and never click links from unexpected messages.
- Keep only a small amount of crypto on any exchange for trading, and withdraw larger holdings to self-custody.
Terms Explained
- hot wallet An online-connected cryptocurrency wallet used by an exchange to process quick deposits and withdrawals.
- cold wallet An offline cryptocurrency wallet not connected to the internet, used to store funds more securely.
- self-custodial wallet A wallet where the user, not the exchange, holds the private keys that control the funds.
- User Protection Fund A pool of assets set aside by an exchange to reimburse customers if a covered security event causes losses.
- on-chain analysis Examination of the public blockchain record to trace how funds move between addresses.
- authorization-signing process The internal step that approves and signs a cryptocurrency transfer before it is sent.
- blockchain A shared digital record of all transactions on a cryptocurrency network.