
Crypto exchange Bitget disclosed a major security breach late Thursday, confirming that attackers siphoned roughly $351.6 million from its hot and warm wallets before the platform could fully contain the intrusion. CEO Gracy Chen said the exchange's security systems first detected unauthorized transfers at 18:31 UTC on September 24, triggering emergency response protocols, though on-chain data shows funds continued moving out of Bitget-linked wallets for nearly three hours afterward — with the final tracked transfer occurring just minutes before the exchange's public notice went out.
Blockchain records show the attacker moved through a rapid sequence of transfers across multiple wallets and networks, draining tens of millions of dollars in stablecoins, ether, and other tokens within the first 30 minutes of detection. Notably, the attacker prioritized converting assets that issuers like Tether and Circle can freeze — such as USDT and USDC — into ether, which cannot be frozen by any central authority, suggesting a deliberate effort to outrun potential asset-recovery efforts. Analysts tracking the flow of funds observed the attacker paying above-market prices to swap stolen stablecoins for ether through decentralized exchange pools, a pattern consistent with attackers racing against a freeze window.
Bitget has paused all customer withdrawals while it investigates the breach, though the company says deposits and trading continue to function normally and its cold storage reserves were not compromised. Chen stated that the full amount of the loss falls within coverage of Bitget's User Protection Fund, which she said holds more than $464 million — providing a cushion, though a relatively thin one, against the scale of the theft. The exchange has published monthly proof-of-reserves attestations for years, most recently reporting reserves well above customer liabilities.
While Bitget has not detailed the specific attack vector, pending a fuller incident report, the company's leadership has pointed to North Korean state-linked hacking operations as the likely source — a pattern consistent with a string of major exchange breaches in recent years attributed to North Korean groups such as Lazarus, which US authorities have tied to billions of dollars in stolen crypto assets funneled toward the regime's weapons programs. Security researchers note that this style of attack typically originates off-chain, through compromised developer credentials or internal access, rather than any flaw in blockchain cryptography itself.
Adding to the chaos, scammers have already begun exploiting the incident by deploying spoofed tokens and lookalike wallet addresses designed to trick users and investigators following the stolen funds on-chain — a now-common secondary threat that emerges in the aftermath of major crypto hacks.
The breach ranks among the largest exchange losses since the record $1.5 billion Bybit hack earlier this year, once again intensifying scrutiny over hot wallet security practices across the crypto industry. Bitget has pledged to release a full incident report and said it will not speculate further on the attack's origin until its investigation concludes.