0x11d5079511d5…11d50792
Bitget Confirms $387.5M Hack, Points to North Korea
Bitget confirmed a $387.5 million hack detected on September 24. CEO Gracy Chen linked the attack to North Korea, citing IP and on-chain patterns. A $464 million protection fund will cover customer losses.
Outputs
Bitget confirmed total losses of $387.5 million, up from $183 million within the first hour of detection at 18:31 UTC on September 24
Roughly 103 million XRP, worth about $157 million, is the single largest component of the haul
A laundering wallet spent $19.67 million in USDT0 to purchase 7,111 ETH via UniswapX and 1inch Fusion in about six minutes
Bitget's User Protection Fund holds more than $464 million and will cover customer losses in full
Withdrawals remain paused; Bitget is set to announce a resumption plan on September 26
Hackers drained roughly $387.5 million from crypto exchange Bitget in an incident the firm detected on September 24, CEO Gracy Chen confirmed in a livestream and a series of X posts. The theft ranks among the largest crypto heists on record and has been preliminarily linked to North Korea-linked actors.
What happened?
Bitget's security systems flagged unauthorized transfers from a subset of its hot wallets at 18:31 UTC on September 24. Within an hour, on-chain investigators had already counted approximately $183 million in stablecoins, Ether and other assets leaving addresses tagged to the exchange.
By the time Bitget publicly acknowledged the breach, the figure had climbed to $351.6 million, then to $387.5 million in the company's latest update. The single largest component of the haul is roughly 103 million XRP, valued at approximately $157 million. The remainder spans at least five blockchains, with assets routed to wallets the attacker controlled.
The breach was not a private-key compromise. Chen said attackers broke into a backend system inside Bitget's wallet infrastructure and used it to spoof transaction data.
"They did not forge user withdrawal requests, nor did they obtain our private keys of the cold wallet and any hot, warm wallet," she said. The exchange's own authorization process approved the transfers because the data appeared routine.
Pseudonymous researcher DCF GOD documented the early laundering trail. A newly created wallet spent $19.67 million in USDT0, a cross-chain variant of Tether, to buy 7,111 ETH through UniswapX and 1inch Fusion in roughly six minutes, paying approximately 5% above market.
Who is behind it?
Chen has pointed cautiously at Pyongyang. "We've identified some IP addresses that match the VPN choices by a certain DPRK group," she said, adding that "the pattern looks very much like what the North Korean team did before."
She has stopped short of confirming attribution and has published no technical evidence. Law enforcement is now investigating, the exchange said.
The profile matches activity the FBI has previously attributed to North Korea's Lazarus Group, also tracked as TraderTraitor. The same cluster was blamed for the $1.4 billion Bybit hack in February 2025, which the bureau formally confirmed weeks later. Blockchain analytics firm Chainalysis put North Korea's 2025 total haul above $2 billion.
Bitget has engaged incident-response firms Mandiant and SlowMist to conduct forensic analysis alongside its internal team. Chen said the company will publish a full root-cause report once remediation is complete.
What about customer funds?
Bitget's User Protection Fund, which holds more than $464 million, will absorb the full loss, Chen said, leaving customer balances intact. The reserve stood at $300 million in 2023, set aside specifically to cover hacks and theft so users would not be left holding the loss.
Deposits and trading remained live throughout the incident. Withdrawals alone were paused as a precaution and remain frozen. Bitget said it will announce a withdrawal-resumption plan on September 26.
Chen disclosed that she has personally been targeted by the same suspected North Korean cluster, losing roughly $80,000 from a personal wallet outside Bitget.
Bitget's withdrawal timing will offer the first concrete signal of operational recovery, with the September 26 plan likely to set the tone for how the exchange handles the post-mortem and any subsequent regulatory inquiries into its wallet-infrastructure controls.
via x.com (Original)