News Report Technology
September 25, 2026

Bitget Confirms $351.6M Hot Wallet Breach, Points To North Korea-Linked Hackers

Bitget Confirms $351.6M Hot Wallet Breach, Points To North Korea-Linked Hackers

Cryptocurrency exchange Bitget confirmed on September 24, 2026, that it detected unauthorized transfers from a limited number of its hot wallets at 18:31 UTC. According to the exchange, approximately $351.6 million in assets were affected, making this one of the largest exchange security incidents since Bybit’s $1.5 billion loss. 

Initial on-chain monitoring had suggested that three hot wallets and one cold wallet were compromised, with more than $170 million moved and swapped into ETH; the exchange later clarified that its three-tier wallet architecture contained the breach to portions of the hot and warm wallet layers, while all cold wallets across every chain were confirmed secure and unaffected.

The stolen assets span multiple chains, including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. The largest single loss occurred on the XRP chain, with roughly 102.9 million XRP valued at about $157.5 million taken. 

Other affected assets included approximately 31,890 ETH, 34.75 million USDT, 21 million USDC, 19.67 million USD₮0, 3,000 XAUt, 12,719 BNB, 821,012 AVAX, and 20.6 million TRX. On-chain investigators reported that the attacker swapped most of the EVM-chain proceeds into nearly 68,000 ETH.

Bitget’s security team stated that hackers breached a critical backend system of the wallet service, forged transfer details, and invoked the authorized signing process to move funds out — explicitly ruling out private key leakage. As a precaution, withdrawals were suspended while deposits and trading remained operational. 

The exchange flagged the abnormal addresses, engaged law enforcement and on-chain security firms, and said several blockchain foundations have already frozen attacker wallets. Bitget committed to hourly updates and a full incident report with root-cause analysis within 24 hours.

Financial Backing and Attribution Concerns

Bitget emphasized that user funds are fully protected, noting the loss falls within its User Protection Fund, which holds more than $464 million in publicly verifiable wallets, and that the exchange additionally maintains over $1 billion in proprietary capital. CEO Gracy Chen stated that the fund alone is sufficient to cover the losses and pushed back against comparisons to FTX, arguing the platform is capable of withstanding a potential withdrawal run. She also confirmed that Bitget Wallet operates on entirely separate infrastructure and was not affected.

Regarding attribution, Chen said the attacker’s identity cannot be confirmed with complete certainty, but evidence points toward North Korea-linked actors. Certain IP addresses involved in the breach closely match VPN patterns used by a DPRK-associated group, and the attack methodology is consistent with their known techniques. Independent analyst Specter linked the stolen XRP, which was bridged, to the $24 million AFX hack from July attributed to the Lazarus Group sub-actor TraderTraitor. Bitget has notified relevant authorities and is cooperating with investigations globally.

The restoration of withdrawals remains pending, with Chen stating that no precise timeline will be committed to until system security is fully confirmed, as remediation across the many affected cryptocurrencies and networks is still underway.

Disclaimer

In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.

About The Author

Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.

More articles
Alisa Davidson
Alisa Davidson

Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.

Hot Stories
Join Our Newsletter.
Latest News

Shufti, Jumio, Sumsub, And Beyond: Top 6 Identity Verification And Compliance Platforms To Know In 2026

Shufti, Sumsub, Incode, Veriff, Persona and Jumio compared on compliance lifecycle coverage, pricing transparency and fraud detection ...

Know More

2026 AI Market Claims Vs SEC Fillings: Linkmate Analysis

Is the AI market really all just PR talk or there's a deeper math going on in ...

Know More
Read More
Read more
BlackRock-Designed Portfolio Strategies Come Onchain Through Ondo’s New Tokenized Products
News Report Technology
BlackRock-Designed Portfolio Strategies Come Onchain Through Ondo’s New Tokenized Products
September 24, 2026
Duelbits Hit By Suspected Private Key Compromise As Losses Approach $6M
News Report Technology
Duelbits Hit By Suspected Private Key Compromise As Losses Approach $6M
September 24, 2026
IBM Bridges Traditional Banking And Blockchain: Swift Ledger Integration And On-Premises Digital Asset Haven Now In Beta
News Report Technology
IBM Bridges Traditional Banking And Blockchain: Swift Ledger Integration And On-Premises Digital Asset Haven Now In Beta
September 24, 2026
ARCANUM Launches Lift: A Spot Trading Algorithm That Works Positions Deep In The Red
News Report Technology
ARCANUM Launches Lift: A Spot Trading Algorithm That Works Positions Deep In The Red
September 24, 2026