Skip to main content
Exchange SecurityIncident Report· 3 min read· in Finance

Bitget Confirms $387.5 Million Loss in Backend System Hack, Suspects North Korea

The cryptocurrency exchange suspended withdrawals after attackers compromised a backend authorization system to drain hot wallets. Bitget says its protection fund will cover the losses and pointed to North Korean hackers based on early evidence.

By Madison Lane

Bitget Management 40%Cybersecurity Analysts 40%Affected Users 20%
Bitget Management
Maintains that the breach is contained and user funds are fully backed by the exchange's protection fund.
Cybersecurity Analysts
Focuses on the sophisticated backend compromise and the ongoing threat of state-sponsored North Korean hackers.
Affected Users
Concerned about the indefinite suspension of withdrawals and the timeline for regaining access to their assets.

Perspectives this story doesn't cover

  • Regulatory Authorities
  • Retail Investors

Fast facts

  • Attackers drained $387.5 million from Bitget's hot wallets by compromising a backend authorization system.
  • The exchange's private keys and offline cold wallets were not affected by the breach.
  • Bitget CEO Gracy Chen attributed the attack to North Korean hacking groups based on IP and on-chain evidence.
  • Withdrawals remain suspended while Mandiant and SlowMist conduct a security review, but Bitget says its protection fund will cover all losses.

Why this matters

The $387.5 million theft ranks among the largest cryptocurrency exchange breaches of the year, testing the viability of exchange protection funds to make users whole. It also highlights a shift in attacker tactics away from stealing private keys and toward exploiting the internal systems that authorize transfers.

A $387.5 million theft—an amount equal to more than 80 percent of the exchange's entire emergency protection fund—was drained from the cryptocurrency platform Bitget on Thursday. Attackers bypassed the platform's private keys entirely by compromising the backend system that authorizes withdrawals, forcing a halt to all customer outflows while the company investigates.[1][2][3]

The unauthorized transfers began at 18:31 UTC on September 24, hitting the exchange's hot and warm wallet infrastructure. Bitget initially estimated the losses at $351.6 million before revising the total upward on Friday to account for additional assets taken across the Zcash and TRON networks.[3]

Bitget CEO Gracy Chen stated that the attackers did not steal the exchange's private keys. Instead, they breached a critical backend component, spoofed transaction data, and manipulated the system into approving the fraudulent transfers itself. The company's offline cold wallets, which require physical authorization outside the network, were not affected by the intrusion.[1][2]

The stolen assets span multiple blockchains, with the total loss revised upward to include Zcash and TRON.

During a town hall address, Chen attributed the attack to North Korean hacking groups. She cited IP addresses, behavioral patterns, and on-chain signatures that align with the state-sponsored actors responsible for billions of dollars in cryptocurrency thefts over the past five years.[1][2]

During a town hall address, Chen attributed the attack to North Korean hacking groups.

The stolen assets span multiple blockchains and include Ethereum, XRP, USDC, and several other major tokens. Blockchain security firms tracked more than $175 million leaving the platform in the initial wave before the larger chunks were consolidated and moved.[2]

Bitget has suspended all customer withdrawals while it conducts a security review alongside the cybersecurity firms Mandiant and SlowMist. The exchange emphasized that customer account balances remain accurate and that deposits and trading services are continuing to operate normally.[2][3]

Bitget has enlisted cybersecurity firms Mandiant and SlowMist to conduct a comprehensive security review of its infrastructure.

The exchange has promised to make users whole using its User Protection Fund, which currently holds more than $464 million. “Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full,” Chen said. She pointed to the survival of other platforms following massive breaches, noting that “if Bybit can hold on [after] a $1.5 billion loss, we can definitely hold on to a $350 million+ loss.”[2]

To incentivize the return of the assets, Bitget established a recovery bounty program. The exchange is offering a 5 percent reward to platforms that voluntarily freeze the attacker's funds, and another 5 percent for successful recoveries. Several platforms have already frozen a portion of the funds connected to the hackers' wallets.[2][3]

The incident highlights a shift in attacker tactics away from cryptographic brute force and toward exploiting the internal administrative systems that manage exchange liquidity. Bitget stated it will not resume withdrawals until the security review confirms the platform is completely safe, leaving users waiting for a definitive timeline on when they can move their assets.[1][2][3]

Viewpoints in depth

Bitget's Containment Strategy

The exchange maintains that the threat is neutralized and user funds are fully backed.

Bitget executives have focused their messaging on financial resilience, pointing to the $464 million User Protection Fund as a definitive backstop for the $387.5 million loss. By emphasizing that cold wallets remained untouched and private keys were not compromised, the exchange is attempting to project operational stability. Management argues that the immediate suspension of withdrawals and the deployment of third-party security firms demonstrate a controlled response, framing the incident as a severe but manageable stress test rather than an existential crisis.

The Cybersecurity Threat Landscape

Security researchers view the breach as part of an escalating campaign by state-sponsored actors.

For blockchain security analysts, the Bitget breach underscores a dangerous evolution in exchange exploits. Rather than attempting to steal cryptographic keys directly, attackers are increasingly targeting the administrative backend systems that authorize transactions. The suspected involvement of North Korean hacking groups aligns with a broader pattern of state-sponsored operations targeting centralized crypto platforms to fund regime activities. Analysts warn that as long as exchanges rely on automated hot wallet approvals, backend spoofing will remain a primary attack vector.

Sources

Source coverage

3 outlets

3 viewpoints surfaced

Bitget Management 40%Cybersecurity Analysts 40%Affected Users 20%
  1. [1]GizmodoCybersecurity Analysts

    North Korea 'Very Likely' Behind $388 Million Hack of Crypto Exchange Bitget

    Read on Gizmodo →
  2. [2]The RecordBitget Management

    Crypto CEO accuses North Korea of stealing $387 million from Bitget platform

    Read on The Record →
  3. [3]The Crypto TimesBitget Management

    Bitget Updates Hack Impact to $387.5M, Offers 5% Recovery Bounty

    Read on The Crypto Times →

Comments

Stay informed

Every angle. Every day.

Get Finance stories with full source coverage and perspective breakdowns delivered to your inbox.