Bitget suffers massive $351.6 million security breach linked to North Korean state-sponsored hackers

Cryptocurrency exchange Bitget has confirmed a catastrophic security breach resulting in the theft of approximately $351.6 million in digital assets. The incident, which occurred late Thursday, has been attributed by the company to North Korean state-sponsored threat actors. The unauthorized transfers originated from the exchange’s hot and warm wallets, prompting an immediate emergency response from the platform’s security team and external cybersecurity partners.
The Anatomy of the Breach
The security failure was detected late Thursday evening when Bitget’s internal automated monitoring systems flagged a series of anomalous, unauthorized transactions. According to internal reports, the attackers managed to bypass standard security protocols by compromising a critical backend system responsible for the exchange’s wallet infrastructure.
By infiltrating this backend layer, the perpetrators were able to spoof transaction data, effectively tricking the system into verifying and authorizing fraudulent outgoing transfers. The breach targeted a diverse array of blockchain networks, including Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, Binance Smart Chain (BSC), and Base. The stolen assets include significant volumes of ETH, XRP, BNB, AVAX, USDT, and USDC.
Bitget CEO Gracy Chen confirmed that the scale of the loss is concentrated in specific tokens, with XRP losses representing the largest single-chain impact. While the investigation into the exact entry point and the nature of the compromised credentials remains ongoing, Bitget has confirmed that no further unauthorized transfers have been detected since the initial discovery.
Chronology of the Incident and Response
The sequence of events unfolded rapidly as Bitget moved to contain the damage:
- Thursday Evening: Automated security alerts triggered by unusual outbound volume from hot and warm wallets.
- Immediate Post-Breach: Bitget’s engineering team initiated emergency protocols, including the temporary suspension of all withdrawal services to prevent further capital flight.
- Early Friday: The exchange publicly disclosed the breach, confirming the $351.6 million figure and initiating collaboration with on-chain security firms SlowMist and Mandiant.
- Ongoing Investigation: Law enforcement agencies were notified immediately. Several blockchain networks involved in the theft have proactively frozen the identified hacker wallet addresses to prevent the attackers from laundering the stolen funds through centralized exchanges or mixers.
- Current Status: Bitget continues to work with forensic investigators to determine how the attackers gained administrative access to the backend authorization process. The exchange has pledged to restore withdrawal functionality only after a comprehensive security audit confirms the environment is stable and fortified against further exploitation.
Protection Funds and Customer Impact
In an effort to stabilize market confidence and prevent a bank run, Bitget emphasized that its User Protection Fund remains fully operational. The fund, which currently holds approximately 5,500 BTC valued at roughly $464 million, is intended specifically for scenarios of insolvency or catastrophic security failure.
"The incident falls within the coverage of Bitget’s User Protection Fund," the company stated in an official release. "Customer account balances remain accurate, and deposits and trading continue to operate normally."
Crucially, the company clarified that its self-custodial Bitget Wallet product was not compromised. Because the self-custodial wallet operates on infrastructure entirely independent of the centralized exchange’s backend, user assets held in those private wallets remain secure.
The North Korean Connection: A Pattern of State-Sponsored Aggression
The attribution of this heist to North Korean actors follows a long-established pattern of state-backed cyber-espionage and financial theft. Analysts from major blockchain intelligence firms have noted that the behavioral patterns—specifically the IP behavior and the specific methodologies used to obfuscate the movement of funds—align with the tactics of groups such as Lazarus and APT38.

North Korea has increasingly turned to the exploitation of decentralized and centralized finance (DeFi/CeFi) platforms to circumvent international sanctions. By siphoning billions of dollars in crypto assets, the regime allegedly funds its domestic ballistic missile and nuclear weapons programs.
The scale of the Bitget heist, while significant, is part of a larger trend. In recent years, North Korean hackers have been linked to some of the most sophisticated cyberattacks in history. Notable incidents include the 2024 Bybit hack, where attackers made off with a record $1.5 billion in Ethereum. Reports from Chainalysis suggest that in 2024 alone, North Korean actors were involved in at least 47 major crypto heists, totaling approximately $1.34 billion in stolen assets. Elliptic’s research further estimates that since 2017, North Korean-linked actors have successfully exfiltrated over $6 billion in cryptocurrency.
Technical and Market Implications
The Bitget breach highlights the persistent vulnerability of centralized exchanges to sophisticated backend attacks. While many exchanges prioritize securing the "front door"—the user-facing login portals—the "back door," involving the internal API keys and server-side signing mechanisms, remains a high-value target for state-sponsored entities.
The use of "warm wallets"—wallets that remain connected to the internet to facilitate rapid trading—represents a necessary but inherent risk in the exchange business model. Unlike cold storage, which is offline and immune to remote network intrusions, warm wallets require constant communication with the exchange’s backend, creating a persistent attack surface.
The fallout from this incident is expected to intensify the regulatory scrutiny on crypto exchanges globally. Financial regulators are likely to demand more rigorous internal controls, particularly regarding the separation of duties in administrative backend systems and the implementation of multi-signature requirements that are not susceptible to single-point-of-failure compromises.
Broader Industry Outlook
For the broader crypto ecosystem, the Bitget incident serves as a stark reminder of the "cat and mouse" game played between exchange security teams and highly motivated, state-funded hackers. The ability of the attackers to forge transfer information suggests a deep level of technical reconnaissance.
As investigators from Mandiant and SlowMist continue their forensic analysis, the industry awaits details on whether the breach involved an insider threat, a zero-day vulnerability in the exchange’s API, or a compromised supply chain component within the wallet infrastructure.
For now, the restoration of trust rests on Bitget’s ability to execute its reimbursement plan via the User Protection Fund. By covering losses, the exchange hopes to mitigate the potential for a liquidity crisis. However, the reputational damage and the long-term cost of hardening systems against future incursions remain significant hurdles for the company.
As the digital asset market continues to mature, the "security-first" mandate is becoming more than a marketing slogan; it is becoming a survival imperative. The Bitget breach is likely to accelerate the adoption of institutional-grade security standards, potentially forcing smaller or less-capitalized exchanges to consolidate or seek security partnerships with larger, more robust entities. The global community remains vigilant, watching the movement of the stolen assets, which likely now sit in various "mixer" protocols, awaiting the next stage of the laundering process—a process the international community continues to struggle to contain.







