Bitget, a leading cryptocurrency exchange, suffered a security breach on September 24, involving approximately $351.6 million in digital assets.
CEO Gracy Chen said on an X livestream that investigators identified IP addresses linked to VPN services previously used by a North Korean hacking group and noted similarities with earlier attacks, although Bitget has not confirmed who was responsible.
The specific method used to gain access to Bitget’s systems remains under technical investigation, conducted in partnership with Mandiant and SlowMist, but the company assures that user funds remain safe.
“Based on our current assessment, approximately $351.6 million in assets were affected. Bitget’s cold wallets and the overwhelming majority of platform assets remain secure and unaffected… Most importantly, user funds remain protected,” Bitget wrote on X.
Chen maintained that the losses are fully covered by its User Protection Fund, which holds more than $464 million. Moreover, she said the breach has been contained, preventing additional unauthorized outflows.
Bitget hack sees XRP as the largest single-chain loss
Current on-chain reporting puts the affected assets roughly at: 102.93M XRP ($157.48M), 31,890 ETH ($85.75M), $34.75M USDT, $21.06M USDC, $19.67M USDT0, 3,000 XAUt ($12.82M), 12,719 BNB ($9.88M), 821,012 AVAX ($8.38M), and 20.59M TRX ($7.07M).
Those figures total about $356.86M, slightly above Bitget’s own $351.6M estimate because of pricing and time differences. XRP alone accounts for roughly 44% of the listed value, while ETH is about 24%.
According to Chen, the attacker compromised a critical backend wallet system, used it to manipulate transfer information, and triggered Bitget’s authorization-signing process. Abnormal transfers from several hot wallets were first detected at 2:31 a.m. on September 25, prompting the cryptocurrency exchange to activate its emergency response procedures, reportedly within minutes. Law enforcement agencies and blockchain security organizations were likewise contacted.
Bitget said the incident did not involve a compromise of its private keys. Preliminary findings instead point to an internal wallet-backend system breach in which transfer data was manipulated before triggering the exchange’s authorization and signing process.
Bitget withdrawals suspended amid security checks
As a precaution, Bitget temporarily suspended withdrawals while it conducts security checks. Deposits and trading remain operational, while the exchange said withdrawals will resume once the verification process is complete.
In a subsequent update, Chen Bitget also said the team had contacted the foundations of the affected blockchain networks, with some reportedly confirming that addresses associated with the suspected attacker had been frozen.
“We have contacted the foundations of all affected chains, and some foundations have confirmed the freezing of hacker wallet addresses. We are fully following up on all feasible channels and will continue to announce the latest progress,” she added.
Also worth mentioning is that Bitget Wallet operates independently of the exchange’s infrastructure and was not affected by the incident. That is, assets held through Bitget Wallet remain secure.
Featured image via Shutterstock