Bitget reports $351.6M loss in suspected North Korean wallet attack

Bitget reports $351.6 million theft from hot and warm wallets
Cryptocurrency exchange Bitget said suspected North Korean threat actors stole $351.6 million from a limited number of its hot and warm wallets after compromising a critical backend system in its wallet infrastructure. The exchange detected unauthorised transfers at 18:31 UTC on September 24, 2026.
Bitget said its cold wallets and the overwhelming majority of platform assets were secure and unaffected. Customer account balances remained accurate, and deposits and trading continued to operate normally. The company temporarily suspended withdrawals while it conducts what it called a comprehensive security review.
Transaction data was spoofed through wallet infrastructure
Chief executive Gracy Chen said the assets affected included ETH, XRP, BNB, AVAX, USDT and USDC. The incident involved Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base.
Bitget said the attacker compromised a critical backend system, used it to spoof transaction data and then triggered the exchange's authorisation process to move funds out. It said no further unauthorised transfers were possible, while the precise intrusion method remained under investigation.
The exchange has contacted the foundations behind the affected chains. Chen said some had confirmed that hacker wallet addresses were frozen. Bitget attributed the activity cautiously, saying IP behaviour patterns and on-chain analysis were highly consistent with known North Korean hacker organisation patterns.
External investigation and separate wallet infrastructure
Bitget has brought in Google-owned Mandiant and blockchain security firm SlowMist for a third-party investigation. It also said Bitget Wallet, a self-custodial product operating on infrastructure separate from Bitget Exchange, was not affected.
The company has not disclosed how the backend system was initially breached. Its account nevertheless places the incident at the point where compromised infrastructure could influence transaction data and an internal authorisation workflow, rather than at individual customer accounts.
The attribution follows reporting by SentinelOne that linked the North Korea-associated TraderTraitor group to an attack on an India-based IT services company. TraderTraitor is known for thefts from Bybit and KelpDAO's LayerZero bridge.
Business implication
For exchanges and other digital-asset businesses, the event underlines the operational importance of independently validating transaction data, isolating wallet infrastructure and having tested controls to pause withdrawals while preserving account records and core services during an investigation.

