Cryptocurrency exchange Bitget says hackers stole approximately $351.6 million after gaining unauthorised access to part of its wallet infrastructure.
The exchange said its security systems detected unauthorised transfers from some of its hot wallets at 18:31 UTC on Thursday, September 24, prompting it to activate its emergency response procedures.
In a security notice, Bitget CEO, Gracy Chen, said the breach was limited to parts of the exchange’s hot and warm wallet infrastructure, while its cold wallets remained secure.
“Estimated funds affected: approximately $351.6 million,” Bitget said.
The exchange temporarily suspended withdrawals following the incident but said deposits and trading remained operational.
Bitget also assured users that the stolen funds were covered by its User Protection Fund, which it said held more than $464 million.
“User funds are safe. The full amount of this loss falls within the coverage of Bitget’s User Protection Fund, which currently holds over $464 million,” the exchange said.
In a subsequent update, Chen said the attackers had compromised a critical backend system within Bitget’s wallet infrastructure.
She said the attackers used the compromised system to manipulate transaction data and trigger the exchange’s authorisation process to transfer funds.
“Private key compromise has been ruled out,” Chen said, adding that Bitget had contained the incident and prevented further unauthorised transfers.
The exchange said, however, that it was still investigating how the attackers gained access to the backend system and would release a detailed technical report once the investigation was completed.
The affected assets included Ethereum, XRP, BNB, Avalanche, USDT, USDC and other tokens across the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Smart Chain and Base networks.
Chen said all on-chain cold wallets had been checked and confirmed to be secure.
Bitget also contacted the foundations and security teams of the affected blockchain networks, with some reportedly moving to freeze wallet addresses linked to the attackers.
Chen said Bitget’s preliminary analysis had found similarities between the attack and techniques associated with known North Korean hacking groups.
“Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organisations,” she said.
She added that Bitget had reported the incident to relevant authorities and was cooperating with a global investigation.
Bitget did not identify a specific group as responsible for the attack.
The company also clarified that Bitget Wallet, its decentralised wallet product, was not affected.
According to Chen, Bitget Wallet operates independently of the exchange’s infrastructure and was not exposed to the breach.
The exchange said technical teams were working on system recovery, remediation and additional security measures.
Bitget has not given a specific timeframe for the restoration of withdrawals, saying it would announce a reopening window once it had been confirmed.
“Our goal is to complete a full recovery as soon as possible. We will announce the specific time window immediately upon confirmation. We will not commit to timelines we cannot deliver on,” Chen said.
Bitget said it had notified law enforcement agencies and blockchain security firms and was pursuing available measures to contain the incident and recover the affected assets.
The exchange said it would continue providing updates and publish a full incident report detailing the root cause of the breach and the corrective measures taken.





