A complete breakdown of the Bitget hack — what the exchange is, who its CEO is, how North Korean hackers allegedly stole $352 million, and what happens next.

Bitget is a Seychelles-registered cryptocurrency exchange founded in 2018, originally launched as a derivatives trading platform before evolving into what it now calls a "universal exchange" — combining spot trading, futures, copy trading, a self-custody wallet, and even tokenized US stock trading under one roof. Starting life under the name BitKeep, Bitget has grown into one of the top five to ten largest crypto exchanges globally by trading volume, serving well over 100 million users across more than 100 countries. The platform has built its brand partly through high-profile sponsorships, including a partnership with football superstar Lionel Messi and Italian club Juventus FC, and by publishing monthly proof-of-reserves reports meant to reassure users of its financial health.
Gracy Chen has served as Bitget's CEO since being promoted from her earlier role as Managing Director. A graduate of the National University of Singapore with an MBA from MIT, Chen built roughly a decade of experience in business management, marketing, and investment before joining the crypto industry, including a stint as an early investor in BitKeep, Bitget's now-rebranded wallet arm. Under her leadership, Bitget has grown from around 20 million to more than 120 million users worldwide, and Chen has become known as the only woman CEO among the world's top ten crypto exchanges. She also leads Bitget's $10 million Blockchain4Her initiative, aimed at promoting gender diversity in the blockchain space, and has been vocal in industry discussions about exchange security standards — an irony not lost on observers given the current breach.

On September 24, 2026, Bitget's security systems detected unauthorized transfers out of its hot and warm wallets at 18:31 UTC. According to blockchain data, the intrusion wasn't instantly contained — funds continued flowing out of Bitget-linked wallets for nearly three hours after detection, with the final tracked transfer occurring just minutes before the exchange's public announcement went live. Total losses are estimated between $351.6 million and $387.5 million, spread across several blockchain networks including Ethereum, BNB Smart Chain, and Avalanche.
A particularly telling detail emerged from on-chain analysis: the attacker quickly converted stolen stablecoins like USDT and USDC — both of which issuers can freeze — into ether, a cryptocurrency that no central authority can freeze. Blockchain investigators noted the attacker was paying above-market prices to make these swaps quickly, suggesting a deliberate race against potential asset freezes. Importantly, Bitget says its cold storage reserves and its separate Bitget Wallet product were untouched, with the breach confined specifically to hot and warm wallet layers used for everyday liquidity.
While Bitget has not released a formal attribution, the company has pointed to North Korean hacking groups as the suspected actors, reportedly based on IP address and VPN usage patterns observed during the breach. This fits a well-documented pattern: North Korean state-linked groups, most notably the Lazarus Group, have been blamed for a string of major exchange hacks in recent years, including the record-breaking $1.5 billion Bybit theft earlier in 2026. US and UN investigators have repeatedly linked such attacks to funding for North Korea's weapons programs, with the FBI naming a specific North Korean cyber campaign, "TraderTraitor," in earlier incidents. Security experts note that these breaches typically don't involve breaking blockchain cryptography itself, but rather compromising off-chain elements — stolen developer credentials, deployment keys, or internal system access.
In the immediate aftermath, Bitget suspended customer withdrawals as a precaution while it investigates the breach, though deposits and spot trading have continued operating normally. CEO Gracy Chen has committed to covering the entire loss through Bitget's User Protection Fund, which she says holds more than $464 million — providing a real, if relatively thin, cushion against the scale of the theft. The company has promised a full incident report within 24 hours of its initial disclosure and says it will avoid speculating further on the exact attack method until that investigation wraps up.
Looking ahead, the key markers to watch will be: whether Bitget successfully restores full withdrawal functionality without further incident, whether the promised incident report identifies concrete security failures, and whether any portion of the stolen funds can be recovered or frozen before they're fully laundered. Complicating recovery efforts, scammers have already begun exploiting the chaos by circulating spoofed tokens and lookalike wallet addresses designed to trick people tracking the stolen funds on-chain.
This breach now ranks among the largest exchange losses since the Bybit hack, and will likely reignite broader industry debate over hot wallet security practices, third-party wallet infrastructure risk, and the effectiveness of user protection funds as a backstop against increasingly sophisticated, state-linked cyberattacks.