Bitget Confirms $387.5 Million Loss in Backend System Hack, Suspects North Korea
The cryptocurrency exchange suspended withdrawals after attackers compromised a backend authorization system to drain hot wallets. Bitget says its protection fund will cover the losses and pointed to North Korean hackers based on early evidence.
By Madison Lane
- Bitget Management
- Maintains that the breach is contained and user funds are fully backed by the exchange's protection fund.
- Cybersecurity Analysts
- Focuses on the sophisticated backend compromise and the ongoing threat of state-sponsored North Korean hackers.
- Affected Users
- Concerned about the indefinite suspension of withdrawals and the timeline for regaining access to their assets.
Perspectives this story doesn't cover
- Regulatory Authorities
- Retail Investors
Fast facts
- Attackers drained $387.5 million from Bitget's hot wallets by compromising a backend authorization system.
- The exchange's private keys and offline cold wallets were not affected by the breach.
- Bitget CEO Gracy Chen attributed the attack to North Korean hacking groups based on IP and on-chain evidence.
- Withdrawals remain suspended while Mandiant and SlowMist conduct a security review, but Bitget says its protection fund will cover all losses.
Why this matters
The $387.5 million theft ranks among the largest cryptocurrency exchange breaches of the year, testing the viability of exchange protection funds to make users whole. It also highlights a shift in attacker tactics away from stealing private keys and toward exploiting the internal systems that authorize transfers.
A $387.5 million theft—an amount equal to more than 80 percent of the exchange's entire emergency protection fund—was drained from the cryptocurrency platform Bitget on Thursday. Attackers bypassed the platform's private keys entirely by compromising the backend system that authorizes withdrawals, forcing a halt to all customer outflows while the company investigates.[1][2][3]
The unauthorized transfers began at 18:31 UTC on September 24, hitting the exchange's hot and warm wallet infrastructure. Bitget initially estimated the losses at $351.6 million before revising the total upward on Friday to account for additional assets taken across the Zcash and TRON networks.[3]
Bitget CEO Gracy Chen stated that the attackers did not steal the exchange's private keys. Instead, they breached a critical backend component, spoofed transaction data, and manipulated the system into approving the fraudulent transfers itself. The company's offline cold wallets, which require physical authorization outside the network, were not affected by the intrusion.[1][2]
During a town hall address, Chen attributed the attack to North Korean hacking groups. She cited IP addresses, behavioral patterns, and on-chain signatures that align with the state-sponsored actors responsible for billions of dollars in cryptocurrency thefts over the past five years.[1][2]
During a town hall address, Chen attributed the attack to North Korean hacking groups.
The stolen assets span multiple blockchains and include Ethereum, XRP, USDC, and several other major tokens. Blockchain security firms tracked more than $175 million leaving the platform in the initial wave before the larger chunks were consolidated and moved.[2]
Bitget has suspended all customer withdrawals while it conducts a security review alongside the cybersecurity firms Mandiant and SlowMist. The exchange emphasized that customer account balances remain accurate and that deposits and trading services are continuing to operate normally.[2][3]
The exchange has promised to make users whole using its User Protection Fund, which currently holds more than $464 million. “Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full,” Chen said. She pointed to the survival of other platforms following massive breaches, noting that “if Bybit can hold on [after] a $1.5 billion loss, we can definitely hold on to a $350 million+ loss.”[2]
To incentivize the return of the assets, Bitget established a recovery bounty program. The exchange is offering a 5 percent reward to platforms that voluntarily freeze the attacker's funds, and another 5 percent for successful recoveries. Several platforms have already frozen a portion of the funds connected to the hackers' wallets.[2][3]
The incident highlights a shift in attacker tactics away from cryptographic brute force and toward exploiting the internal administrative systems that manage exchange liquidity. Bitget stated it will not resume withdrawals until the security review confirms the platform is completely safe, leaving users waiting for a definitive timeline on when they can move their assets.[1][2][3]
Viewpoints in depth
Bitget's Containment Strategy
The exchange maintains that the threat is neutralized and user funds are fully backed.
Bitget executives have focused their messaging on financial resilience, pointing to the $464 million User Protection Fund as a definitive backstop for the $387.5 million loss. By emphasizing that cold wallets remained untouched and private keys were not compromised, the exchange is attempting to project operational stability. Management argues that the immediate suspension of withdrawals and the deployment of third-party security firms demonstrate a controlled response, framing the incident as a severe but manageable stress test rather than an existential crisis.
The Cybersecurity Threat Landscape
Security researchers view the breach as part of an escalating campaign by state-sponsored actors.
For blockchain security analysts, the Bitget breach underscores a dangerous evolution in exchange exploits. Rather than attempting to steal cryptographic keys directly, attackers are increasingly targeting the administrative backend systems that authorize transactions. The suspected involvement of North Korean hacking groups aligns with a broader pattern of state-sponsored operations targeting centralized crypto platforms to fund regime activities. Analysts warn that as long as exchanges rely on automated hot wallet approvals, backend spoofing will remain a primary attack vector.
Sources
[1]GizmodoCybersecurity AnalystsNorth Korea 'Very Likely' Behind $388 Million Hack of Crypto Exchange Bitget
Read on Gizmodo →
[2]The RecordBitget ManagementCrypto CEO accuses North Korea of stealing $387 million from Bitget platform
Read on The Record →
[3]The Crypto TimesBitget ManagementBitget Updates Hack Impact to $387.5M, Offers 5% Recovery Bounty
Read on The Crypto Times →
Comments
More in Finance
See all →Tokenized Assets
ARK Invest Launches Tokenized Venture Fund on Ethereum Following SEC Clearance
6 sources
Credit Card Disputes
The 60-Day Timeline and Required Documentation for Disputing a Credit Card Charge Under the Fair Credit Billing Act
6 sources
Capital Requirements
The Standardized Approach Formula That Dictates Bank Capital Requirements Under Basel III
6 sources
Berkshire Portfolio
Berkshire Hathaway Takes $37.8 Billion Stake in Alphabet in Major Tech Shift
5 sources
Every angle. Every day.
Get Finance stories with full source coverage and perspective breakdowns delivered to your inbox.




