Bitget Confirms $351.6 Million Theft From Hot and Warm Wallets
Cryptocurrency exchange Bitget disclosed that suspected North Korean hackers stole $351.6 million from its hot and warm wallet infrastructure, in one of the largest exchange security breaches reported so far in 2026. Bitget's security systems flagged unauthorized transfers at 18:31 UTC on September 24, 2026, and the exchange says its cold wallets were not affected and customer account balances remain accurate. CEO Gracy Chen said preliminary evidence — including IP addresses matching VPN infrastructure previously tied to a DPRK-linked hacking group — points toward North Korean involvement, though she stressed the attribution is not yet confirmed.
Incident at a Glance
| Attribute | Value |
|---|---|
| Victim | Bitget (cryptocurrency exchange) |
| Amount stolen | $351.6 million |
| Detection time | 18:31 UTC, September 24, 2026 |
| Wallets affected | Hot wallets and warm wallets (cold wallets unaffected) |
| Suspected actor | North Korea-linked group (attribution preliminary, per CEO Gracy Chen) |
| Attack method | Backend compromise + spoofed transaction data, not private-key theft |
| Largest single loss | |
| Also stolen | 31,890 ETH; ~$75M in stablecoins (USDT0) |
| Chains involved | Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, Base |
| Response | Withdrawals suspended; deposits and trading continued |
| Forensic partners | Mandiant, SlowMist |
| Compensation | Bitget's User Protection Fund (5,500 BTC, ~$464M) to cover all losses |
How It Worked
Not a Private-Key Theft
According to Chen, this was not a conventional exchange hack. The attackers did not obtain the private keys controlling Bitget's cold, hot, or warm wallets. Instead, Chen said, "the attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out." Rather than forging withdrawal requests from customer accounts, the attacker appears to have breached Bitget's own systems or servers directly and pushed the transfers through the exchange's own authorization pipeline.
The Warm Wallet Layer Was Also Breached
The compromise reached beyond the hot wallets used for day-to-day liquidity into the warm wallet layer — a semi-connected buffer tier that refills hot wallets and periodically sweeps excess deposits into cold storage. Bitget's three-tier wallet architecture (hot, warm, cold) is designed so that a breach of the internet-facing layer should not cascade into the offline reserve; in this case the compromise was contained before reaching cold storage, but it crossed from the hot layer into the warm layer first.
Multi-Chain Asset Movement
Blockchain researchers, including Arkham Intelligence analysts, tracked the stolen funds moving across multiple chains — Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. The single largest loss was roughly 102.9 million XRP (about $157.5 million), which the attacker split across five wallets — four holding 20 million XRP each and a fifth holding 22,976,677 XRP — a pattern consistent with efforts to complicate freezing and tracing. Also stolen were 31,890 ETH and approximately $75 million in stablecoins (USDT0). Early on-chain estimates put the visible outflow at roughly $183 million before Bitget's full disclosure of the $351.6 million total.
Attribution Still Preliminary
Chen said investigators "identified some IP addresses that match the VPN choices by a certain DPRK group," and that the attack's patterns resembled earlier North Korean operations. However, Bitget has not yet published a completed forensic report tying a specific group to the breach, and no government agency has publicly attributed the incident to Pyongyang. Independent on-chain investigators have floated a possible link between the stolen XRP and funds traced to the smaller $24 million AFX Trade hack, attributing both to the TraderTraitor cluster associated with the Lazarus Group, though this too remains an outside analysis rather than a confirmed finding.
Insider Threat Considered, Not Confirmed
Chen also addressed speculation that a Bitget employee may have been involved, saying the company does not currently believe the breach was an inside job — while acknowledging investigators have not completely ruled it out.
Impact Assessment
| Impact Area | Description |
|---|---|
| Direct financial loss | $351.6 million drained from hot and warm wallets |
| Customer funds | Bitget says balances are accurate and will be made whole via its User Protection Fund |
| Operational | Withdrawals suspended as a precaution; deposits and trading continued uninterrupted |
| Reputational | One of the largest exchange breaches of 2026, drawing comparisons to Bybit's $1.5B theft |
| Industry-wide | Reinforces backend/authorization systems — not just private keys — as a viable attack surface for exchange-scale theft |
| Attribution risk | Preliminary DPRK linkage could trigger sanctions exposure for any platform that processes the stolen funds |
Recommendations
For Exchange Operators
- Treat backend systems that generate or authorize wallet transactions as critical attack surface, equal to private-key custody — this breach bypassed key theft entirely by spoofing data inside the authorization pipeline.
- Apply defense-in-depth between wallet tiers: a compromise of the hot-wallet-facing backend should not be able to reach warm-wallet sweep logic without independent, out-of-band verification.
- Maintain a well-funded, transparent user protection/insurance reserve and be prepared to disclose incidents and remediation timelines quickly — Bitget's continued deposits/trading and hourly-update commitment limited the operational and trust fallout.
For Security and Threat Intelligence Teams
- Track wallet addresses and consolidation patterns from this incident (including the five-way XRP wallet split) for reuse across other suspected DPRK operations, consistent with prior campaigns like the Bybit and Drift heists.
- Coordinate early with blockchain foundations and exchanges capable of freezing flagged addresses; several already froze attacker-linked wallets in this case, which can materially reduce realized losses even after funds move.
- Treat "no private key theft" attack narratives as a reminder to audit internal backend authorization logic, not just key management, during incident response tabletop exercises.
For Bitget Users and Crypto Holders Generally
- Confirm account balances through official Bitget channels and avoid acting on unsolicited "recovery" or "compensation" messages referencing the hack, a common follow-on phishing vector after high-profile breaches.
- Where possible, prefer self-custody or hardware wallets for long-term holdings rather than leaving significant balances on any single exchange, regardless of its wallet-tier architecture.
- Monitor official Bitget communications for the promised full forensic incident report before drawing final conclusions about attribution or root cause.
Key Takeaways
- Bitget lost $351.6 million from hot and warm wallets on September 24, 2026, while cold wallets and customer balances remained unaffected.
- The attack did not involve private-key theft — attackers allegedly compromised a backend system and spoofed transaction data to trigger Bitget's own authorization process.
- Stolen assets spanned seven blockchains, with the largest single loss (~$157.5M) in XRP, split across five wallets to complicate tracing.
- Attribution to North Korea is preliminary, based on IP/VPN evidence cited by CEO Gracy Chen — not yet confirmed by an independent forensic report or government agency.
- Bitget's User Protection Fund (5,500 BTC, ~$464M) is intended to cover all customer losses, and withdrawals were suspended only as a precaution while deposits and trading continued.
- The incident adds to a lengthening 2026 pattern of large-scale crypto thefts linked to DPRK-affiliated actors, following incidents like the $280 million Drift heist and the $1.5 billion Bybit theft attributed to TraderTraitor.