Invest1 publisher3 min readPublished
Covering Bitget's $351 million hack would use three-quarters of its user protection fund
Bitget CEO Gracy Chen ties a $351 million breach of the exchange's online wallets to North Korean hackers and says a $464 million user fund covers it. Paying it out could leave about $113 million in reserve while withdrawals stay frozen and Bitget still cannot say how the attackers got in.
The Investor · Invest desk

What happened
- Bitget suspended withdrawals on Thursday after spotting suspicious fund transfers, and alerted law enforcement and security firms.
- Attackers took ETH, XRP, AVAX and BNB, plus USDC, USDT and USDT0 on Arbitrum, in a hack put at $351 million.
- In a live Q&A on X, CEO Gracy Chen tied the attack to VPNs frequently used by North Korean state-sponsored groups.
- Chen said the attackers breached Bitget's systems directly and did not use customers' withdrawal channels.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- cost If the $464 million is a pre-payout balance, making customers whole leaves about $113 million behind the rest of the exchange, and a repeat breach would overrun it by about $238 million.
- constraint Until Bitget finds every affected server it cannot show the breach is closed, so for now customers pay in frozen access to balances the fund says are covered.
- exposure One exchange server breach yielded about 33 times what WaterPlum's fake-recruiter campaign against 7,000 wallets moved in eight months. For the groups Chen suspects, exchange signing systems are the bigger target.
If the $464 million Chen cited is the fund's balance before it absorbs this loss [7], covering the full $351 million [1] uses about 76% of it [1] and leaves roughly $113 million [2] behind every other balance on the exchange. A second breach of the same size would overrun that remainder by about $238 million [3]. "User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million," Chen said [7]. Recoveries would shrink the bill. Chen said some stolen funds are already back, and the exchange is pursuing the rest with blockchain foundations and industry security partners [10].
The money came out of the online wallets, or rather out of a portion of them, and the cold wallets were secure, according to Chen [6]. Bitget did not disclose how much it kept online, so the share of its online holdings that was drained is unknown [6]. For custody, how the attackers got in matters more than which wallet they emptied. Chen said it was a direct system breach and that customer withdrawal channels were not used [8]. She also said the exchange has yet to identify all the affected servers or understand fully how the attackers got past its defenses [9].
TRM Labs has said North Korean groups systematically target back-end infrastructure over source code, and that a digital-asset firm's highest-risk areas are key management and cryptographic signing setups [16]. In my view the Bitget case supports that claim better than it supports a ranking of hot wallets against cold ones. The split did its job here: the loss stopped at whatever was sitting online [6]. One exchange with its cold storage intact is still a single observation. While the server inventory is incomplete, Chen's assurance about the cold wallets rests on an investigation she describes as unfinished [6][9].
Chen said Bitget had identified some IP addresses that match the VPN choices of a certain DPRK group, and that the pattern looks very much like what the North Korean team did before [3]. If the attribution holds, Bitget's loss alone equals about 59% of the $600 million in crypto North Korea was tied to in the first half of this year, and about 17% of the $2.02 billion attributed to it last year [12][4][5].
WaterPlum, another North Korean group, posed as recruiters and hid trojans in sample assignments handed to job seekers [17]. According to reports from the FBI and agencies in Japan, Australia and Germany, it compromised about 7,000 wallets across more than 100 countries and routed over $10.7 million to Pyongyang between December 2025 and July 2026 [13]. One server breach at one exchange took roughly 33 times as much [6].
Bybit, which lost roughly $1.5 billion in February 2025 in a hack blockchain investigators attributed to Lazarus Group [14], will help Bitget trace and recover the coins, its CEO Ben Zhou said [15].
The unfinished server review could turn up more compromised machines, and with them a loss larger than $351 million [9]. Recoveries could also come in large enough that the fund barely moves [10]. The view that the hot/cold split held would be wrong if the review finds the attackers reached systems tied to cold storage. Until it is done, withdrawals stay suspended [11].
What to watch
- Bitget reopening withdrawals, and whether it names the entry point when it does.
- An attribution from law enforcement or a forensics firm that confirms or replaces Chen's IP-address and VPN evidence.
- A published User Protection Fund balance after the payout, showing whether about $113 million is what actually remains.