Bitget has confirmed a massive security breach resulting in the loss of approximately $387.5 million in crypto assets, detected on September 24 at 18:31 UTC. The incident is believed to be the largest crypto hack of the year. Attackers did not steal private keys or forge user withdrawal requests; instead, they compromised Bitget’s backend wallet infrastructure to spoof transaction data, tricking the exchange’s authorization process into approving legitimate-looking transfers from hot and warm wallets. The stolen haul includes roughly 103 million XRP, valued at about $157 million, alongside stablecoins and Ethereum moved across at least five blockchains.
CEO Gracy Chen stated that law enforcement is investigating and that forensic analysis by Mandiant and SlowMist is ongoing. Chen noted that IP addresses and on-chain signatures match techniques used by North Korea’s state-linked hacking groups, though the attacker’s identity remains unconfirmed. To mitigate impact, Bitget froze withdrawals while keeping deposits and trading active. The exchange’s User Protection Fund, which holds more than $464 million, will cover the full loss, ensuring customer account balances remain intact. Chen also revealed she was personally targeted by the same group previously, losing about $80,000 from an external wallet.
The Bitget incident underscores a critical vulnerability in centralized exchange infrastructure: the risk of internal system compromise rather than direct key theft. By exploiting the authorization logic within the wallet backend, attackers bypassed traditional perimeter defenses focused on cold storage security. This method highlights how sophisticated social engineering or technical manipulation of transaction approval workflows can drain significant liquidity from hot and warm wallets without triggering immediate alarms associated with unauthorized access attempts. The rapid escalation of losses from $183 million to $387.5 million within hours suggests that detection mechanisms may have lagged behind the speed of automated fund movement across multiple chains.
From a regulatory and institutional adoption perspective, the suspected involvement of North Korean actors reinforces the persistent threat landscape facing major crypto platforms. While Bitget’s ability to absorb the loss through its User Protection Fund prevents immediate customer harm, it raises questions about the sustainability of such reserves against increasingly large-scale attacks. The industry must now scrutinize whether current compliance frameworks and operational risk protocols are sufficient to detect and halt spoofed transactions in real-time. Continued collaboration between exchanges, forensic firms like Mandiant and SlowMist, and law enforcement will be essential to confirm attribution and potentially recover assets, setting a precedent for how the market responds to state-sponsored cyber threats.


