Security7 publishers2 min readPublished
Bitget's CEO says attackers took $351.6M by breaching the exchange's own servers
Bitget CEO Gracy Chen says attackers breached the exchange's own servers to move $351.6 million out of its hot wallets on September 24. She blames North Korea's Lazarus Group without published technical evidence, and how the transfers were authorized is still unexplained.
The Watch · Security desk

What happened
- Bitget found the breach Thursday evening, when its security systems flagged multiple unauthorized transfers out of a limited number of its crypto wallets.
- CEO Gracy Chen said the losses span seven chains, including Ethereum, XRP Ledger, Arbitrum and Base, and that XRP was the largest single-chain loss.
- Bitget said its cold wallets and most platform assets were untouched, and its self-custodial Bitget Wallet, which runs on separate infrastructure, was not affected.
- All withdrawals are suspended, while deposits and trading continue and customer balances remain accurate, according to the company.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- cost Bitget's reserve pays for this theft, which uses up about 76% of the fund and leaves roughly $112 million to cover any further loss.
- contradiction Bybit's $1.5 billion loss came out of an ETH cold wallet. Bitget's untouched cold storage limited this theft, but that does not show offline wallets cap exchange losses.
- constraint A theft on Bybit's scale would be about 3.2 times Bitget's fund, more than the reserve that makes customers whole here could absorb.
Bitget's account puts the failure in the data path that feeds its signer. "The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out," Bitget CEO Gracy Chen said [8]. By the company's description, its own authorization-signing process released the funds after acting on forged transfer information [7]. The company has not said how the intruder got into the backend wallet service [7]. Chen said the method "remains under active investigation" [8].
Containment, as Bitget describes it, is holding. "No further unauthorized transfers are possible," Chen said [8]. Some chains have frozen the attacker's wallet addresses since the theft, according to Chen [10]. Bitget said it will restore withdrawals once investigators confirm it is safe to resume normal operations [16].
The fund paying for this is held in bitcoin. It is 5,500 BTC, which Bitget valued at about $464 million, or roughly $84,400 a coin [12][5]. Those 5,500 BTC cover a $351.6 million loss only while bitcoin trades above about $63,900. That price is roughly 24% below the valuation Bitget gave [3].
The North Korea attribution on record comes from Bitget, through Chen. "Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations," Chen said [11]. Mandiant and SlowMist are assisting, alongside law enforcement and on-chain security institutions [6]. The reporting cites no finding from any of them. If Chen's attribution holds, Bitget is the latest in a run of major crypto thefts that BleepingComputer links to North Korean hackers [14].
What to watch
- Whether Mandiant or SlowMist publish how the backend wallet service was breached, and whether their findings back Bitget's North Korea attribution.
- The date Bitget restores withdrawals, and whether it draws on the 5,500 BTC fund before a move in bitcoin's price narrows the coverage margin.
- How much of the $351.6 million sits in the attacker addresses that some chains have frozen.