Advertisement

Bitget loses $351.6 million in hack but its customers lose nothing

Bitget loses $351.6 million in hack but its customers lose nothing

Crypto exchange Bitget lost an estimated $351.6 million after attackers breached a critical backend system, spoofed transfer data and pushed fraudulent withdrawals through the platform’s own authorization process.

The exchange detected unauthorized transfers from parts of its hot and warm wallet infrastructure at 18:31 UTC on Sept. 24. Deposits and trading remain open, but withdrawals have been suspended while technical teams complete a security review.

CEO Gracy Chen said the attack did not involve stolen private keys, drawing an important line between a compromised signing credential and a failure in the controls surrounding it.

“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” Chen wrote on X. “Private key compromise has been ruled out.”

The keys stayed safe. The gatekeeper did not.

Every crypto wallet relies on a public key, which can be shared to receive funds, and a private key, which proves ownership and authorizes spending. If a private key is copied, an attacker can continue signing transactions until the assets are moved or the wallet is abandoned.

Chen says that is not what happened at Bitget. Instead, the attackers allegedly fed forged transaction information into a compromised backend system and persuaded the exchange’s normal approval machinery to sign off on it. In simpler terms, the vault key stayed in place, but the paperwork reaching the teller was fake.

The distinction is less alarming than a private-key theft, but it is not less serious. It points to weaknesses in the systems that decide what gets signed, and whether internal safeguards can stop a valid authorization process from approving invalid instructions.

North Korea is suspected, not confirmed

Chen said investigators found internet protocol addresses linked to VPN services previously used by a North Korean hacking group. She also said the attack resembled earlier operations attributed to the country, making North Korean involvement a leading line of inquiry.

That attribution remains preliminary. The method used to gain entry to Bitget’s systems is still under technical investigation, and similarities in infrastructure or behavior are not proof of identity on their own.

The breach involved 19 transfers across several networks and assets, including ether, XRP, USDT, USDC, Avalanche and BNB. Early on-chain estimates put the outflows at roughly $183 million, before Bitget said activity across additional blockchains brought the total exposure to $351.6 million.

Bitget maintains that customer balances remain accurate and that the loss is fully covered by its User Protection Fund, which the company says holds more than $464 million. Cold wallets, where the bulk of assets are stored offline, were not affected.

A three-year UAE push without a full trading license

The timing also puts Bitget’s regulatory ambitions under a brighter light. The exchange’s push into the UAE dates back roughly three years, to its 2023 expansion drive in Dubai, but it still does not appear on the Virtual Assets Regulatory Authority’s public register as a fully licensed exchange.

Bitget obtained a commercial Innovation license from the Dubai International Financial Centre in 2025. That license supports a local corporate presence and collaboration with the region’s fintech ecosystem, but it does not authorize Bitget to provide virtual-asset trading services. At the time, the company said it was working toward a trading license under VARA’s supervision.

In 2024, Bitget had noted that 10% of its user based was from the MENA region.

Dubai’s licensing process is designed to test more than market demand. Applicants are expected to demonstrate governance, operational resilience, compliance controls and technology safeguards before they can serve customers. A breach of this scale will inevitably sharpen questions around those controls, even if the loss is absorbed without affecting customer balances.

The next test is not the size of the fund

Bitget says the incident has been contained and no further unauthorized transfers are possible. The exchange has flagged the receiving addresses, contacted law enforcement and enlisted blockchain-security firms to trace the funds. Bybit CEO Ben Zhou also said his team was standing by to assist, returning support Bitget offered after Bybit’s $1.5 billion hack in February 2025.

The immediate question for users is when withdrawals will resume. Chen said the pause could last hours or days, but “shouldn’t take weeks.”

The larger question is whether Bitget can show exactly how a forged request traveled far enough through its internal systems to become an approved transfer. A protection fund can cover a hole in the balance sheet. It cannot, on its own, explain how the gate opened.

Advertisement

Subscribe To Our Newsletter

Stay updated with the latest crypto news, blockchain insights, and market analysis. Get exclusive content delivered straight to your inbox.

By subscribing, you agree to our Privacy Policy and consent to receive updates.