- Scale of the breach: Bitget lost $351.6 million in the hack, hitting hot and warm wallets while cold storage stayed untouched.
- Suspected actor: IP and VPN evidence points to a North Korea-linked group, echoing patterns from the $1.5 billion Bybit hack in 2025.
- User funds covered: Bitget’s $464 million User Protection Fund exceeds the stolen amount, so customer balances remain fully backed despite the breach.
Bitget confirmed a $351.6 million security breach on September 24, 2026, after attackers accessed part of its wallet system. The exchange later said evidence points to a North Korea-linked hacking group behind the attack.
What Happened in the Bitget Hack
The Bitget hack was first detected at 18:31 UTC on September 24. Security systems flagged unauthorized transfers moving out of the exchange. Chen said the transfers came from parts of the hot and warm wallet infrastructure. Cold wallets, which store funds offline, were not touched during the Bitget hack.
Nineteen separate transfers carried assets away from Bitget’s systems that day. The stolen tokens included Ether, XRP, USDT, USDC, Avalanche, and BNB. These assets moved across five different blockchain networks, including Ethereum and Arbitrum. Early on-chain tracking placed losses near $183 million, but Bitget later raised that figure after reviewing every affected chain.
Bitget said the attacker did not steal private keys during the breach. Instead, the intruder broke into a backend wallet system and spoofed transfer data. This trick tricked Bitget’s authorization process into approving fake outflows. The exchange said it contained the breach quickly, stopping further losses from the Bitget hack.
North Korea Link Emerges in Bitget Hack Investigation
Bitget CEO Gracy Chen addressed the public directly hours after the Bitget hack. Speaking on a live broadcast on X, she shared early findings from the internal probe. Investigators traced certain IP addresses back to VPN services. Those same VPN choices had appeared in past attacks tied to North Korea.
Chen explained the pattern this way during her livestream:
“We’ve identified some IP addresses that match the VPN choices by a certain DPRK group.”
She stopped short of naming a specific unit, though outside researchers pointed toward North Korea’s Lazarus Group. An independent on-chain researcher separately linked wallet behavior in the Bitget hack to known North Korean crime patterns. Chen said her team ruled out an inside job, despite Bitget employing close to 2,000 staff members.
North Korean hacking groups have a long track record in crypto theft. State-linked actors stole roughly $2.02 billion in digital assets during 2025 alone. That total includes the Bybit hack, worth about $1.5 billion, which the FBI attributed to North Korea. The Bitget hack, if confirmed, would extend that pattern into a new exchange.
Bitget Hack Impact on Users and Funds
Bitget suspended withdrawals right after discovering the breach, aiming to stop further losses. Deposits and trading continued as normal throughout the response to the Bitget hack. The company said customer account balances stayed accurate the entire time.
Chen pointed to Bitget’s User Protection Fund as the backstop for affected users. That fund held more than $464 million before the breach occurred. Since the stolen amount sits below that figure, the fund can cover the full loss. Chen also said some stolen funds had already been recovered, though she gave no exact figure.
| Detail | Information |
| Amount stolen | $351.6 million |
| Date detected | September 24, 2026, 18:31 UTC |
| Wallets affected | Hot and warm wallets |
| Wallets safe | Cold wallets |
| Transfers involved | 19 unauthorized transfers |
| Networks hit | Ethereum, XRP Ledger, Avalanche, BNB Smart Chain, Arbitrum |
| Suspected actor | North Korea-linked group |
| User Protection Fund | Over $464 million |
| Withdrawal status | Suspended, expected to resume within days |
Chen gave no fixed date for restoring withdrawals following the Bitget hack. She said the process would take hours or days rather than weeks. Bitget’s technical team is repairing and reinforcing the systems the attacker exploited. The exchange promised a full incident report within 24 hours of the event.
What Happens Next
Bitget is now working alongside law enforcement agencies and blockchain security firms. These partners aim to trace stolen funds and freeze wallets where possible. Blockchain foundations have also joined the recovery effort tied to the Bitget hack. Tracking funds across five networks adds complexity to the investigation.
The exchange has flagged the wallet addresses that received stolen funds. This step helps other platforms block transactions linked to the Bitget hack. Chen said her team will keep releasing updates as the probe continues. Full technical details on how the attacker entered the system remain under wraps for now.
The broader crypto industry will likely watch this case closely. Exchanges often adjust their wallet security setups after major breaches like this one. Whether Bitget changes its wallet architecture following the hack remains to be seen.
1. How much money did Bitget lose in the hack?
Bitget confirmed a loss of about $351.6 million across several blockchain networks.
2. Are Bitget user funds safe after the hack?
Yes. Bitget’s User Protection Fund, worth over $464 million, covers the full loss.
3. Is North Korea confirmed to be behind the Bitget hack?
Not fully confirmed. Bitget cited IP and VPN evidence pointing toward a North Korean group.
4. Can I still deposit or trade on Bitget?
Yes. Deposits and trading stayed active; only withdrawals were paused during the review.




