Crypto World

Bitget probe points to backend breach after $351.6M hack

Published

on

Bitget has said its preliminary probe into a $351.6 million wallet breach found no private-key leak, while withdrawals remain suspended after unauthorized transfers on September 24, 2026.

Summary

  • $351.6 million in assets were affected after Bitget detected unauthorized wallet transfers on September 24.
  • Bitget says private keys stayed secure, while attackers breached systems and transferred funds directly off-platform.
  • Withdrawals remain suspended, while deposits and trading continue during Bitget’s ongoing security review and repairs.
  • Lookonchain estimates XRP was the largest stolen asset, with 102.93 million tokens worth $157.48 million.
  • Gracy Chen says North Korean involvement remains unconfirmed despite preliminary IP and VPN similarities found.

Bitget’s official security notice states that its systems detected the transfers at 18:31 UTC and activated emergency procedures within minutes. The exchange estimated that approximately $351.6 million in assets were affected and said the incident reached portions of its hot and warm wallet layers. Cold wallets remained secure under Bitget’s internal three-tier classification, the company said.

The exchange temporarily stopped withdrawals while leaving deposits and trading open. Bitget said customer account balances remained accurate and its User Protection Fund, valued at more than $464 million, could cover the estimated loss. Law enforcement agencies and on-chain security firms have been notified, while addresses tied to the abnormal transfers have been flagged.

Advertisement

Advertisement

Bitget says private keys were not exposed

During a live Q&A after the breach, CEO Gracy Chen said investigators had ruled out a leak of private keys used by Bitget’s cold, warm and hot wallets. Chen said attackers entered Bitget’s systems and transferred funds directly, without using customer withdrawal requests. Investigators were still working to determine the precise entry point.

A report on the same live session said Bitget’s security team had identified part of the attack route. The preliminary finding described a compromise of a core backend wallet service, where false transfer data reached the exchange’s approval-signature process. Bitget has not yet published the technical evidence behind that finding, leaving the exact intrusion method under review.

Chen said measures intended to prevent further outflows had been completed. Engineering teams were still repairing systems, strengthening security controls and preparing withdrawal services for reopening. No fixed restart time had been announced by early September 25.

The first public notice had avoided naming an attack method. Bitget wrote, “We will not speculate on the attack vector until the investigation is complete.” Its subsequent backend-system finding therefore remains preliminary until the promised root-cause report is released.

Advertisement

As crypto.news reported after the $1.4 billion Bybit theft in 2025, forensic investigators traced that attack to compromised Safe infrastructure. Investigators said Bybit’s own security systems remained intact during that incident.

On-chain tracking puts XRP at the top of stolen assets

On-chain estimates have continued changing as researchers identify more addresses and assets. Lookonchain placed the stolen portfolio at roughly $356.8 million using token prices when it published its update, slightly above Bitget’s approximately $351.6 million internal estimate. The figures come from separate accounting methods and should not be treated as identical measurements.

Lookonchain listed 102.93 million XRP worth $157.48 million as the largest component. Its breakdown included 31,890 ETH valued near $85.75 million, 34.75 million USDT, 21.05 million USDC, 19.67 million USD₮0, 3,000 XAUt, 12,719 BNB, 821,012 AVAX and 20.59 million TRX. The figures remain an external on-chain estimate, not Bitget’s final transaction-level accounting.

Earlier blockchain tracking produced lower totals because analysts were following publicly labeled wallets while the transfers were still unfolding. Wu Blockchain recorded visible Bitget-linked flows of roughly $178 million to $190 million before the exchange disclosed its internal estimate.

Advertisement

North Korea link remains preliminary

Chen raised a possible North Korean connection during the live Q&A, but she stopped short of confirming who carried out the breach. She said investigators had identified IP addresses matching VPN services used by a North Korean hacking group.

“We’ve identified some IP addresses that match the VPN choices by a certain DPRK group,” Chen said. She later described the observed pattern as similar to previous North Korean operations. Bitget said it did not currently believe the incident involved an insider.

Advertisement

No government agency had publicly attributed the Bitget breach to North Korea in the latest information reviewed. Investigators were still examining the affected systems, infrastructure and method used to enter the platform. Chen’s comments therefore represent Bitget’s preliminary suspicion, not a confirmed attribution.

North Korea has previously been formally linked to major exchange thefts. As crypto.news reported in August, Bybit filed a U.S. federal lawsuit against North Korea, its Reconnaissance General Bureau and the Lazarus Group over the February 2025 theft. The FBI had previously attributed the Bybit attack to North Korean actors.

Crypto.news has separately covered North Korea-linked operations that drained $577 million from Drift Protocol and KelpDAO in April 2026. Those cases involved different attack paths and do not establish who carried out the Bitget breach. North Korea-linked crypto attacks in 2026

Withdrawals stay paused as Bitget prepares full report

Bitget’s withdrawal suspension notice says withdrawals will return only after the security review is complete. Deposits and trading remain available, while technical teams continue system recovery and security work.

Advertisement

During the live Q&A, Chen said some stolen funds had been recovered, although she did not disclose an amount. She said Bitget was working with blockchain foundations and other partners on recovery efforts. No independently verified total for frozen or recovered assets had been disclosed in the latest updates reviewed.

The protection fund remains part of Bitget’s response to the loss. The company says it holds more than $464 million and can cover the approximately $351.6 million affected, while customer account balances remain accurate. Bitget has not yet published a transaction-by-transaction reconciliation explaining the difference between its estimate and Lookonchain’s later market-value calculation.

Bitget has promised a full incident report containing its root-cause analysis and corrective actions within 24 hours of the original security notice. The notice was published on September 24 at 21:39 UTC, putting the detailed report within a September 25 timetable under the company’s stated commitment.

Advertisement




Source link

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version