Bitget says unauthorized transfers totaling $351.6 million were made from parts of its wallet infrastructure. The exchange says its User Protection Fund, which it claims holds more than $464 million, covers the full amount. Withdrawals remain suspended during a security review, while deposits and trading continue.
Bitget CEO Gracy Chen said the incident was detected within minutes and emergency response procedures were activated. Chen also said cold wallets remained secure. In a livestream, she described a suspected compromise of a backend system connected to the wallet infrastructure, where attackers allegedly manipulated transaction data to trigger the exchange's authorization process.
Why it matters
The suspected method, if confirmed, would point to a compromise of systems handling wallet transactions rather than a theft of private keys. Bitget has not confirmed an attack vector, and its investigation is ongoing. The exchange says it does not currently believe the incident was an inside job.
Chen said preliminary findings included IP addresses matching VPN services associated with a North Korean hacking group and similarities to earlier attacks attributed to North Korean operators. She described North Korean involvement as “very likely,” not confirmed. Attribution remains a key open question as investigators examine the evidence.
Market impact
The protection fund's claimed $464 million balance exceeds the reported $351.6 million loss, but users still face a withdrawal freeze with no reopening date announced. Bitget says customer balances remain accurate and protected, and that trading and deposits continue uninterrupted.
Bloomberg reported that Chen said a full incident report, including root-cause analysis and corrective actions, would follow within 24 hours of disclosure. The security review and that report are the next milestones for users assessing when withdrawals may resume and how the breach occurred.
Frequently asked questions
-
How much did Bitget report stolen in the wallet incident?
Bitget reported $351.6 million in unauthorized transfers from parts of its wallet infrastructure.
-
Can Bitget's User Protection Fund cover the reported loss?
Bitget claims the fund holds more than $464 million and covers the full reported loss of $351.6 million.
-
Are Bitget withdrawals available while the review continues?
No. Withdrawals remain suspended during the security review, and Bitget has not announced a reopening date. Deposits and trading continue.
-
Has Bitget confirmed North Korean hackers were responsible?
No. Gracy Chen described North Korean involvement as “very likely” based on preliminary findings, but attribution remains unconfirmed.
-
What has Bitget said about how the attackers moved funds?
Chen described a suspected backend-system compromise involving manipulated transaction data that allegedly triggered the exchange's authorization process. Bitget has not confirmed the attack vector.
Crypto News