Bitget has confirmed a massive security breach resulting in the loss of approximately $387.5 million in crypto assets, detected on September 24 at 18:31 UTC. The incident is believed to be the largest crypto hack of the year. Attackers did not steal private keys or forge user withdrawal requests; instead, they compromised Bitget’s backend wallet infrastructure to spoof transaction data, tricking the exchange’s authorization process into approving legitimate-looking transfers from hot and warm wallets. The stolen haul includes roughly 103 million XRP, valued at about $157 million, alongside stablecoins and Ethereum moved across at least five blockchains.

CEO Gracy Chen stated that law enforcement is investigating and that forensic analysis by Mandiant and SlowMist is ongoing. Chen noted that IP addresses and on-chain signatures match techniques used by North Korea’s state-linked hacking groups, though the attacker’s identity remains unconfirmed. To mitigate impact, Bitget froze withdrawals while keeping deposits and trading active. The exchange’s User Protection Fund, which holds more than $464 million, will cover the full loss, ensuring customer account balances remain intact. Chen also revealed she was personally targeted by the same group previously, losing about $80,000 from an external wallet.