Skip to content

Invest1 publisher3 min readPublished

Covering Bitget's $351 million hack would use three-quarters of its user protection fund

Bitget CEO Gracy Chen ties a $351 million breach of the exchange's online wallets to North Korean hackers and says a $464 million user fund covers it. Paying it out could leave about $113 million in reserve while withdrawals stay frozen and Bitget still cannot say how the attackers got in.

The Investor · Invest desk

Illustration accompanying Covering Bitget's $351 million hack would use three-quarters of its user protection fund

What happened

  • Bitget suspended withdrawals on Thursday after spotting suspicious fund transfers, and alerted law enforcement and security firms.
  • Attackers took ETH, XRP, AVAX and BNB, plus USDC, USDT and USDT0 on Arbitrum, in a hack put at $351 million.
  • In a live Q&A on X, CEO Gracy Chen tied the attack to VPNs frequently used by North Korean state-sponsored groups.
  • Chen said the attackers breached Bitget's systems directly and did not use customers' withdrawal channels.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • cost If the $464 million is a pre-payout balance, making customers whole leaves about $113 million behind the rest of the exchange, and a repeat breach would overrun it by about $238 million.
  • constraint Until Bitget finds every affected server it cannot show the breach is closed, so for now customers pay in frozen access to balances the fund says are covered.
  • exposure One exchange server breach yielded about 33 times what WaterPlum's fake-recruiter campaign against 7,000 wallets moved in eight months. For the groups Chen suspects, exchange signing systems are the bigger target.

If the $464 million Chen cited is the fund's balance before it absorbs this loss [7], covering the full $351 million [1] uses about 76% of it [1] and leaves roughly $113 million [2] behind every other balance on the exchange. A second breach of the same size would overrun that remainder by about $238 million [3]. "User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million," Chen said [7]. Recoveries would shrink the bill. Chen said some stolen funds are already back, and the exchange is pursuing the rest with blockchain foundations and industry security partners [10].

The money came out of the online wallets, or rather out of a portion of them, and the cold wallets were secure, according to Chen [6]. Bitget did not disclose how much it kept online, so the share of its online holdings that was drained is unknown [6]. For custody, how the attackers got in matters more than which wallet they emptied. Chen said it was a direct system breach and that customer withdrawal channels were not used [8]. She also said the exchange has yet to identify all the affected servers or understand fully how the attackers got past its defenses [9].

TRM Labs has said North Korean groups systematically target back-end infrastructure over source code, and that a digital-asset firm's highest-risk areas are key management and cryptographic signing setups [16]. In my view the Bitget case supports that claim better than it supports a ranking of hot wallets against cold ones. The split did its job here: the loss stopped at whatever was sitting online [6]. One exchange with its cold storage intact is still a single observation. While the server inventory is incomplete, Chen's assurance about the cold wallets rests on an investigation she describes as unfinished [6][9].

Chen said Bitget had identified some IP addresses that match the VPN choices of a certain DPRK group, and that the pattern looks very much like what the North Korean team did before [3]. If the attribution holds, Bitget's loss alone equals about 59% of the $600 million in crypto North Korea was tied to in the first half of this year, and about 17% of the $2.02 billion attributed to it last year [12][4][5].

WaterPlum, another North Korean group, posed as recruiters and hid trojans in sample assignments handed to job seekers [17]. According to reports from the FBI and agencies in Japan, Australia and Germany, it compromised about 7,000 wallets across more than 100 countries and routed over $10.7 million to Pyongyang between December 2025 and July 2026 [13]. One server breach at one exchange took roughly 33 times as much [6].

Bybit, which lost roughly $1.5 billion in February 2025 in a hack blockchain investigators attributed to Lazarus Group [14], will help Bitget trace and recover the coins, its CEO Ben Zhou said [15].

The unfinished server review could turn up more compromised machines, and with them a loss larger than $351 million [9]. Recoveries could also come in large enough that the fund barely moves [10]. The view that the hot/cold split held would be wrong if the review finds the attackers reached systems tied to cold storage. Until it is done, withdrawals stay suspended [11].

What to watch

  • Bitget reopening withdrawals, and whether it names the entry point when it does.
  • An attribution from law enforcement or a forensics firm that confirms or replaces Chen's IP-address and VPN evidence.
  • A published User Protection Fund balance after the payout, showing whether about $113 million is what actually remains.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories