Bitget Suffers $351.6 Million Security Breach
Bitget suspended withdrawals after hackers stole $351.6 million in digital assets, an attack CEO Gracy Chen linked to North Korean hacking groups.
Crypto exchange Bitget suspended withdrawals on September 24, 2026, after detecting unauthorized transfers from its hot and warm wallet infrastructure. CEO Gracy Chen estimated that approximately $351.6 million in assets were affected, including Ether, XRP, USDt, USDC, Avalanche, and BNB. This internal estimate exceeded early on-chain reports from Arkham Intelligence, which initially placed losses between $174 million and $183 million.
Chen stated that attackers breached a critical backend wallet system to spoof transfer information and trigger authorized signing processes. While she ruled out the compromise of private keys, she noted that IP addresses and VPN patterns suggest the attack is highly likely linked to North Korean hackers. Bitget maintains that its cold wallets remained secure and that user account balances are accurate.
The exchange reported that its User Protection Fund, valued at over $464 million, along with $1 billion in capital, is sufficient to cover the losses. While deposits and trading remained operational, withdrawals stayed suspended as technical teams repaired systems. Bybit CEO Ben Zhou announced that Bybit is updating its LazarusBounty platform to assist in tracing the stolen funds. Bitget is currently collaborating with law enforcement and on-chain security firms to investigate the incident.