Crypto exchange Bitget lost $351.6 million worth of assets on September 24, 2026, at 18:31 UTC. The breach occurred without involving any private key theft.
Bitget CEO Gracy Chen explained that the attackers broke in through the wallet backend system. From there, they forged transaction data to bypass the exchange’s internal approval process. Chen likened the attackers’ method to physical bank fraud. “It is like slipping a fake withdrawal slip into a bank teller window from inside the office,” she said. The master vault key was not stolen, but the perpetrators forged fund disbursement approval documents directly from within the system.
IP Traces Point to North Korea
Initial investigations by the security team mapped part of the intrusion path. The attack began with a compromise of core wallet backend services, enabling the attackers to push forged transfer data through to the final signature approval process. The system compromise directly affected hot and warm wallets. Thanks to a three-tier security classification system, all funds stored in Bitget’s cold wallets were spared from the hack.
Management has reported the incident to law enforcement agencies and several on-chain security firms. All crypto wallet addresses that received abnormal transfers from Bitget have now been flagged. Based on IP clues left behind by the perpetrators, CEO Chen suspects the involvement of a North Korean hacking group. The confirmation of the $351.6 million loss figure also clarifies initial reports that had estimated the loss at $183 million.
Withdrawals Suspended, Funds Claimed Safe
In response to the breach, Bitget immediately suspended all asset withdrawal activities from the platform. The freeze policy does not stop all services - users can still make deposits and continue trading activities. The exchange has not yet announced a specific timeline for when withdrawal features will reopen. They promised to release a full technical report once the internal investigation is complete.
For users, compensation guarantees remain the primary focus. Chen assured that the exchange has the financial capacity to absorb losses resulting from the exploit. Bitget’s User Protection Fund is currently valued at over $464 million. That reserve fund is claimed to be sufficient to fully cover the estimated $351.6 million loss. While the suspension of withdrawal services forces users to wait, the existence of an emergency fund exceeding the total loss sets this breach apart from an insolvency crisis.
Reported via CoinDesk.
Previously: Bitget Breached for $351M Without Private Keys - CEO Accuses North Korean Hackers
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




