Hackers steal $351.6 million in Bitget crypto exchange hack
Bitget, a cryptocurrency exchange, disclosed a theft of approximately $351.6 million from its hot and warm wallets by suspected North Korean hackers. The breach was detected after unauthorized transfers were flagged, leading to a temporary suspension of withdrawals. The company's cold wallets and most platform assets remain secure, and the User Protection Fund will cover the losses. The attack involved multiple blockchain networks and assets, with some hacker wallet addresses frozen. The specific intrusion method is under investigation, and no further unauthorized transfers are possible. Customer balances remain accurate, and deposits and trading continue normally.
AI Analysis
Technical Summary
Suspected North Korean hackers compromised a critical backend wallet-service system at Bitget, enabling them to spoof transaction data and trigger authorization to transfer approximately $351.6 million from hot and warm wallets. The attack affected multiple blockchain networks including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base, and involved various tokens such as ETH, XRP, BNB, AVAX, USDT, and USDC. Bitget's cold wallets and the majority of platform assets were not affected. The User Protection Fund, holding about $464 million, will cover the losses. The company has frozen some hacker wallet addresses and is cooperating with law enforcement and cybersecurity firms. Withdrawals remain suspended pending investigation and safety confirmation.
Potential Impact
The theft resulted in a direct loss of approximately $351.6 million from Bitget's hot and warm wallets. Despite the breach, cold wallets and most platform assets remain secure, and customer account balances are unaffected. Deposits and trading operations continue normally. The User Protection Fund will cover the financial losses, mitigating direct financial impact on customers. The incident disrupts withdrawal services temporarily and may affect customer trust and exchange reputation.
Mitigation Recommendations
Bitget has suspended withdrawals to prevent further unauthorized transfers and is investigating the breach with law enforcement and cybersecurity experts. The company has frozen some hacker wallet addresses and confirmed no further unauthorized transfers are possible. The User Protection Fund covers all losses, and customer balances remain accurate. Users should monitor official Bitget communications for updates on withdrawal resumption. No additional user action is currently required as the self-custodial Bitget Wallet was not affected.
Hackers steal $351.6 million in Bitget crypto exchange hack
Description
Bitget, a cryptocurrency exchange, disclosed a theft of approximately $351.6 million from its hot and warm wallets by suspected North Korean hackers. The breach was detected after unauthorized transfers were flagged, leading to a temporary suspension of withdrawals. The company's cold wallets and most platform assets remain secure, and the User Protection Fund will cover the losses. The attack involved multiple blockchain networks and assets, with some hacker wallet addresses frozen. The specific intrusion method is under investigation, and no further unauthorized transfers are possible. Customer balances remain accurate, and deposits and trading continue normally.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Suspected North Korean hackers compromised a critical backend wallet-service system at Bitget, enabling them to spoof transaction data and trigger authorization to transfer approximately $351.6 million from hot and warm wallets. The attack affected multiple blockchain networks including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base, and involved various tokens such as ETH, XRP, BNB, AVAX, USDT, and USDC. Bitget's cold wallets and the majority of platform assets were not affected. The User Protection Fund, holding about $464 million, will cover the losses. The company has frozen some hacker wallet addresses and is cooperating with law enforcement and cybersecurity firms. Withdrawals remain suspended pending investigation and safety confirmation.
Potential Impact
The theft resulted in a direct loss of approximately $351.6 million from Bitget's hot and warm wallets. Despite the breach, cold wallets and most platform assets remain secure, and customer account balances are unaffected. Deposits and trading operations continue normally. The User Protection Fund will cover the financial losses, mitigating direct financial impact on customers. The incident disrupts withdrawal services temporarily and may affect customer trust and exchange reputation.
Defensive Guidance
Bitget has suspended withdrawals to prevent further unauthorized transfers and is investigating the breach with law enforcement and cybersecurity experts. The company has frozen some hacker wallet addresses and confirmed no further unauthorized transfers are possible. The User Protection Fund covers all losses, and customer balances remain accurate. Users should monitor official Bitget communications for updates on withdrawal resumption. No additional user action is currently required as the self-custodial Bitget Wallet was not affected.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/","fetched":true,"fetchedAt":"2026-09-25T08:47:51.230Z","wordCount":715}
Threat ID: 6ab63537f7a7c541068ee91b
Added to database: 09/25/2026, 08:47:51 UTC
Last enriched: 09/25/2026, 08:47:57 UTC
Last updated: 09/25/2026, 22:22:09 UTC
Views: 43
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.