Bitget says ~$352M stolen in suspected North Korean hack; withdrawals paused
Bitget CEO Gracy Chen says North Korea's Lazarus Group likely stole roughly $352 million from the exchange's hot and warm wallets, with withdrawals paused and most losses covered by a protection fund.
Crypto exchange Bitget lost roughly $352 million in a hack it now attributes, tentatively, to North Korea, according to Protos, citing statements from Bitget CEO Gracy Chen. The theft coincided with the exchange's eighth-anniversary marketing push.
The trouble surfaced on 24 September, when large withdrawals moved out of addresses tagged as Bitget hot and cold wallets, per Protos. Crypto investigator Specter Analyst tied the activity to the Lazarus Group, the North Korean hacking collective. In a subsequent livestream, Chen said the attack "displays the signs of" a North Korean operation — a characterization, not a confirmed attribution, and one that as of this writing rests on Chen's own account plus Specter Analyst's analysis rather than an independent forensic finding.
Chen's technical account, as relayed by Protos: this was not a private-key compromise. Instead, she said, attackers breached the backend of Bitget's wallet services, forged transfer details, and authorized their own signing processes. Cold wallets reportedly held; the hot and "warm" wallet layers were hit. Bitget's separately branded Bitget Wallet product was not affected, she said.
On funds, Chen said user balances are safe, with most of the loss covered by Bitget's User Protection Fund — which she said "currently holds over $464 million." That figure comes from Bitget itself and hasn't been independently verified. Notably, $464 million against a stated $352 million loss leaves the fund covering the shortfall only if that balance is real, liquid, and not already committed elsewhere; none of that has been demonstrated publicly.
Bitget said it has engaged Mandiant and SlowMist to investigate, and confirmed on the morning of 25 September that withdrawals remain temporarily paused.
Key facts
- ~$352 million stolen; loss initially expected to be lower (Protos, citing Chen).
- Suspected attacker: Lazarus Group / North Korea — attribution by Specter Analyst; Chen says it shows North Korean hallmarks (Protos).
- Method claimed: backend breach of wallet services, forged transfers, self-authorized signing — not a key compromise (Chen, via Protos).
- Cold wallets secure; hot and warm layers hit; Bitget Wallet unaffected (Chen, via Protos).
- User Protection Fund said to hold "over $464 million" (Bitget's figure, via Protos).
- Investigators: Mandiant and SlowMist; withdrawals paused as of 25 September (Protos).
The real-world read
Every substantive claim here — the loss size, the cause, the fund balance, "user funds are safe" — traces to Bitget or its CEO, an interested party mid-incident, relayed through a single secondary outlet. Treat the exchange's own numbers as unverified until Mandiant or SlowMist reports. The attribution to North Korea is convenient (it frames Bitget as the victim of a state-level adversary rather than of its own backend controls), and it currently rests on Chen and one investigator, not published forensics. The most consequential detail is the one Chen volunteered: if there was no key compromise, the "wallet services backend" itself let attackers forge transfers and self-authorize signing — an internal-controls failure. The loss reportedly grew from early estimates, so the $352M figure may still move.
This is news, not financial advice.
Sources
- Protos (Tier 2, reputable secondary), "Bitget's eighth birthday ends with a $352M hack," 25 September 2026 — sole source for the loss figure, Chen's livestream claims, the Specter Analyst attribution, the fund balance, and the investigator engagement. Not sponsored; note that most underlying figures originate with Bitget itself.