Cryptocurrency exchange Bitget has disclosed that hackers stole approximately $351.6m after gaining unauthorised access to part of its wallet infrastructure.
The exchange said its security systems detected unauthorised transfers from some of its hot wallets at 18:31 UTC on Thursday, September 24, prompting it to activate its emergency response protocols.
In an initial security notice signed by Bitget Chief Executive Officer, Gracy Chen, the exchange said the breach was limited to parts of its hot and warm wallet layers, while its cold wallets remained secure.
“Estimated funds affected: approximately $351.6 million,” Bitget said.
The exchange temporarily suspended withdrawals as a precaution but said deposits and trading remained operational.
It also assured users that the loss was covered by its User Protection Fund, which it said held more than $464m.
“User funds are safe. The full amount of this loss falls within the coverage of Bitget’s User Protection Fund, which currently holds over $464 million,” the exchange said.
In a subsequent update, Chen said the attackers had compromised a critical backend system within Bitget’s wallet infrastructure, which they used to manipulate transaction data and trigger the authorisation process for the transfer of funds.
“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” she said.
Chen said an investigation had ruled out the compromise of private keys and that further unauthorised transfers had been prevented.
“Private key compromise has been ruled out, this excludes the more severe risk scenarios. Loss containment is confirmed. No further unauthorized transfers are possible,” she said.
However, Bitget said the specific method used to gain access to the backend system remained under investigation and that a full technical report would be released after the findings were confirmed.
The affected assets included ETH, XRP, BNB, AVAX, USDT, USDC and other tokens across the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base networks.
Chen said all on-chain cold wallets had been confirmed secure and unaffected.
She added that Bitget had contacted the foundations of the affected blockchain networks, with some confirming that wallet addresses linked to the attackers had been frozen.
On the possible identity of the attackers, Chen said Bitget’s analysis found similarities with known North Korean hacking operations.
“Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations,” she said.
She said the exchange had reported the incident to relevant institutions and was cooperating with a global investigation.
Chen also clarified that Bitget Wallet, the exchange’s decentralised wallet product, was not affected.
“Bitget Wallet operates completely independently from Bitget exchange infrastructure, and this incident has no impact on it whatsoever,” she said.
Bitget said several technical teams were working on system remediation and security hardening before withdrawals could be fully restored.
The exchange said it would not announce a timeframe until one had been confirmed.
“Our goal is to complete a full recovery as soon as possible. We will announce the specific time window immediately upon confirmation. We will not commit to timelines we cannot deliver on,” Chen said.
Bitget said it had notified law enforcement agencies and blockchain security firms and was pursuing available channels to contain the incident and recover the stolen assets.
The exchange also said it would provide hourly updates and publish a full incident report covering the root cause and corrective measures within 24 hours.



