Cryptocurrency exchange Bitget has disclosed that approximately $351.6 million was lost after hackers gained unauthorised access to part of its wallet infrastructure.
The exchange said its security systems detected suspicious transfers from some of its hot wallets at 18:31 UTC on Thursday, September 24, prompting the activation of its emergency response protocols.
In an initial security notice signed by Bitget CEO Gracy Chen, the exchange said the incident was limited to parts of its hot and warm wallet infrastructure, while its cold wallets remained secure.
“Estimated funds affected: approximately $351.6 million,” Bitget said.
Following the incident, Bitget temporarily suspended withdrawals as a precaution, while deposits and trading continued.
The exchange assured users that their funds were protected by its User Protection Fund, which it said contained more than $464 million.
“User funds are safe. The full amount of this loss falls within the coverage of Bitget’s User Protection Fund, which currently holds over $464 million,” the exchange said.
In a subsequent update, Chen provided further details about the attack, saying hackers had compromised a critical backend system within Bitget’s wallet infrastructure.
She said the attackers used the compromised system to manipulate transaction data and trigger the exchange’s authorisation process, enabling them to move funds.
Chen said the investigation had ruled out a private-key compromise and that further unauthorised transfers had been prevented.
“Private key compromise has been ruled out; this excludes the more severe risk scenarios. Loss containment is confirmed. No further unauthorized transfers are possible,” she said.
However, Bitget said the exact method used to gain access to the backend system remained under investigation. The exchange said it would publish a detailed technical report once its findings had been confirmed.
Read Also: renaissance-africa-energy-launches-oil-spill-prevention-initiative-in-rivers-state
The affected assets included ETH, XRP, BNB, AVAX, USDT, USDC and other tokens across the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base networks.
Chen said all on-chain cold wallets had been verified as secure and unaffected.
She added that Bitget had contacted the foundations of the affected blockchain networks, with some confirming that wallet addresses linked to the attackers had been frozen.
On the possible identity of the attackers, Chen said Bitget’s preliminary analysis indicated similarities with known North Korean hacking operations.
“Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations,” she said.
Chen said Bitget had reported the incident to relevant institutions and was cooperating with a global investigation.
She also clarified that Bitget Wallet, the exchange’s decentralised wallet product, was not affected because it operates independently of the exchange’s infrastructure.
“Bitget Wallet operates completely independently from Bitget exchange infrastructure, and this incident has no impact on it whatsoever,” she said.
On the resumption of withdrawals, Bitget said its technical teams were working on system remediation and additional security measures but declined to provide a timeline until one could be confirmed.
“Our goal is to complete a full recovery as soon as possible. We will announce the specific time window immediately upon confirmation. We will not commit to timelines we cannot deliver on,” Chen said.
The exchange said it had also notified law enforcement agencies and blockchain security firms and was pursuing available measures to contain the incident and recover the affected assets.
Bitget had earlier pledged to provide hourly updates and publish a comprehensive incident report detailing the root cause and corrective measures within 24 hours.
