Bitget logo on smartphone screen with blurred trading chart background
TECHNOLOGY

Bitget Probe Points to Backend Breach After $351.6M Hack

Image Credit: Shutterstock

Bitget says attackers breached part of its internal wallet infrastructure and transferred about $351.6 million from hot and warm wallets, while its preliminary investigation has found no evidence that private keys were stolen.

The exchange detected unauthorized transfers at 18:31 UTC on Sept. 24 and suspended withdrawals while it investigates the entry point. Cold wallets were unaffected, while deposits and regular exchange trading remain available.

Bitget Traces 19 Transfers to Compromised Wallet Backend

CEO Gracy Chen said the incident involved 19 unauthorized transfers from Bitget’s hot and warm wallet infrastructure.

Chen said Bitget’s preliminary investigation points to a critical backend system used by its wallet service. Attackers were able to fabricate transfer information that reached the exchange’s authorized signing process without obtaining private keys or submitting fraudulent customer withdrawal requests.

The exact method used to compromise the backend remains under investigation. Chen said containment measures have been completed and Bitget has not identified an ongoing risk of further unauthorized transfers.

External on-chain reconstruction has traced roughly $192.6 million across EVM-compatible networks. A separate transaction reconstruction identified 102.98 million XRP, bringing measured receipts to about $350.66 million at the historical prices used in that analysis, close to Bitget’s $351.6 million preliminary estimate.

Withdrawals Remain Paused During Security Review

Bitget has kept withdrawals offline while engineers review the affected systems and determine when services can restart safely. Its separate Bitget On-chain trading service is also temporarily unavailable during the security review.

The exchange says customer account balances remain accurate and that its User Protection Fund, valued above $464 million before the incident, is sufficient to cover the amount affected.

Bitget has notified law enforcement and on-chain security companies and is working with ecosystem partners to identify and recover stolen assets. Chen said some funds have already been recovered but did not disclose an amount.

North Korea Attribution Remains Preliminary

Chen said investigators identified IP addresses and VPN-use patterns resembling infrastructure associated with a North Korea-linked hacking group.

The attribution remains preliminary. Bitget has not publicly identified a specific group or released forensic evidence establishing who carried out the attack.

Bitget has said it will publish a full incident report covering the root cause and corrective measures. Withdrawals remain paused while the security review continues, with no confirmed reopening time announced.

More For You

Explore More News