"Based on our current assessment, approximately $351.6 million in assets were affected," Bitget said, describing a theft the company now attributes to suspected North Korean hackers.
Bitget’s statement, coverage, and customer protections
Bitget disclosed the breach after its security systems flagged multiple unauthorized transfers from a limited number of crypto wallets. The company has temporarily suspended all withdrawals while investigators assess damage and confirm it is safe to restore normal operations. Bitget said deposits and trading continue to operate normally and that customer account balances remain accurate.
Bitget also said its User Protection Fund — which currently holds 5,500 BTC, approximately $464 million at the time of the announcement — will cover all losses from the incident. The exchange emphasized that its cold wallets and the overwhelming majority of platform assets remain secure and unaffected. Bitget further said its self-custodial Bitget Wallet was not impacted because it operates on infrastructure independent of Bitget Exchange.
Chains, assets, and the scale of the theft
Bitget CEO Gracy Chen said the incident involved transfers across multiple blockchains: Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC (Binance Smart Chain), and Base. Assets affected included ETH, XRP (noted as the largest single‑chain loss), BNB, AVAX, USDT, USDC, and other tokens. The company quantified the loss at approximately $351.6 million taken from hot and warm wallets.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleHow Bitget says the intrusion worked
According to the company, the attacker compromised a critical backend system within Bitget’s wallet infrastructure, used that access to spoof transaction data, and triggered the platform’s authorization-signing process to move funds out. Bitget said the specific method of system intrusion remains under active investigation and that it has not yet shared detailed technical information on how attackers accessed the backend wallet‑service system.
CEO Gracy Chen stated that “no further unauthorized transfers are possible,” and that some chains have confirmed hacker wallet addresses have been frozen since the attack.
Investigation partners, law enforcement, and attribution
Bitget said it is investigating the incident with help from law enforcement agencies, on-chain security institutions, and cybersecurity experts at Mandiant and SlowMist. The company linked the theft to North Korean hackers, saying the attribution is based on IP behavior patterns and on-chain analysis and that “the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations.” Bitget said it has reported the attack to relevant institutions and is fully cooperating in a global investigation.
The company also referenced precedent: the source notes that North Korean hackers have previously been linked to other major crypto thefts, including the Bybit incident that resulted in $1.5 billion taken from an ETH cold wallet.
What this means for technologists, regulators, and affected users
- Technologists and security teams: expect deeper forensic work on the backend wallet‑service system Bitget identified — the company has not yet detailed the intrusion vector, and investigators from Mandiant and SlowMist are involved in the active probe.
- Regulators and law enforcement: will be closely involved in the global investigation Bitget described; the firm has already notified relevant institutions and is cooperating with law enforcement agencies.
- Affected users and traders on Bitget: trading and deposits remain active and customer balances are reported as accurate; withdrawals are suspended until investigators confirm it is safe to resume, and losses will be covered by Bitget’s User Protection Fund.
Bitget’s immediate public account provides clear markers: the scope ($351.6 million), the chains and tokens affected, the decision to temporarily freeze withdrawals, and assurance that a dedicated protection fund will cover losses. What remains unresolved in the company’s disclosure is the detailed technical route the attackers used to breach the backend wallet-service system — an explanation investors, customers, and investigators are waiting for before normal withdrawal operations resume.




