Invest12 publishers2 min readPublished Updated
Bitget's preliminary probe blames a backend wallet service for its $351.6 million loss
Bitget's preliminary probe traces a $351.6 million loss to false transfer data fed into its signing approvals, and says no private keys leaked. If the promised root-cause report confirms that, depositors' risk sits in the exchange's backend, because the keys and cold wallets held.
The Investor · Invest desk

What happened
- Bitget's systems caught unauthorized transfers leaving some hot wallets at 18:31 UTC on September 24, and the exchange now puts the loss at $387.5 million.
- Chief executive Gracy Chen said attackers broke into a backend wallet system and spoofed transaction data so Bitget's own authorization process approved the payouts.
- The largest single piece of the haul was about 103 million XRP worth roughly $157 million, and the assets moved across at least five blockchains.
- Chen said Bitget's User Protection Fund, which holds more than $464 million, will cover the full loss and customer account balances stay intact.
- Deposits and trading kept running through the incident while withdrawals were frozen as a precaution.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- cost Bitget's own reserve pays for this hack, and making customers whole takes up to about 84% of the fund's balance.
- exposure Counterparties that judged exchange risk by how keys are stored were exposed anyway. By Chen's account, the weak point was the transaction data Bitget's approval process accepted as genuine.
- constraint Until withdrawals reopen, customers hold balances they cannot move, so the fund's promise has not yet been tested against real payout demand.
A freshly created wallet spent $19.67 million in USDT0 on 7,111 ETH in six minutes, according to the pseudonymous researcher DCF GOD, who flagged it before Bitget had confirmed anything [7]. It paid roughly 5% above market through UniswapX and 1inch Fusion [7]. That works out to about $2,766 per ETH [3], and a premium of roughly $940,000 for the speed [4].
"They did not forge user withdrawal requests, nor did they obtain our private keys of the cold wallet and any hot, warm wallet," chief executive Gracy Chen said [5]. Her version is preliminary. Chen wrote that the investigation with Mandiant and SlowMist is ongoing and that thorough forensic analysis takes more than 24 hours [14].
If her account holds, I think the diligence question for anyone with balances at an exchange is what the signing system checks before it approves a transfer. The follow-up is whether a compromised internal system can feed that check false data, as Chen says happened here [6]. The view fails if the forensics turn up a stolen credential or key. Bitget would then be an ordinary custody failure. It is incomplete if the loss keeps growing, as it already has, from roughly $183 million in the first hour to $351.6 million when Bitget went public and $387.5 million a day later [3][4]. For users, the reserve matters more than the method, since Chen says their balances stay whole either way [10].
The cost falls on that reserve. Paying $387.5 million out of a fund of more than $464 million leaves at least $76.5 million [1]. That is about a quarter of the $300 million the fund held in 2023, when it was set aside to cover hacks and theft [12][6]. The source does not say what assets the fund holds. The $387.5 million is itself a market valuation, and about 40% of it is the XRP position [5], so the dollar cost of replacing the stolen coins moves with one token's price.
Chen has been careful on attribution. "We've identified some IP addresses that match the VPN choices by a certain DPRK group," she said, adding that "the pattern looks very much like what the North Korean team did before" [13]. She stressed that the attacker's identity has not been confirmed [13]. In the Bybit case, a $1.4 billion loss in February 2025, the FBI confirmed North Korean involvement weeks later [15].
What to watch
- When Bitget reopens withdrawals, and whether outflows clear at normal speed against balances the fund has promised to back.
- Whether Bitget publishes a plan and timetable for refilling the protection fund after the payout.
- Any official attribution from the law enforcement agencies Bitget says are now investigating.