Bitget Hack Hits Ethereum (ETH) and USDT for $388M in North Korea-Linked Breach
Bitget confirmed a North Korea-linked hack draining about $388M in Ethereum, TRON and USDT. Cold storage untouched; a $464 million fund covers users.
AI SummaryAI
- Bitget confirmed roughly $388 million drained from hot and warm wallets detected September 24.
- Bitget CEO Gracy Chen linked the attack method to known North Korean hacker organizations.
- Stolen assets were mostly ethereum, tron and USDT, with no bitcoin in the main haul.
- The attacker holds over $28.8 million in bitcoin according to a stolen-funds tracker.
Bitget Confirms North Korea-Linked $388M Breach
Crypto exchange Bitget lost close to $388 million in digital assets to attackers the company links to North Korea, its CEO confirmed Friday, revising upward an incident first detected at 18:31 UTC on September 24. The Seychelles-based venue — the sixth-largest exchange in the market, clearing more than $1 billion in daily trading volume — saw unauthorized transfers leave a portion of its hot and warm wallets. Security researchers flagged the irregular on-chain movements in real time, and Bitget froze withdrawals shortly after the breach surfaced. CEO Gracy Chen said the higher tally “reflects a more complete accounting of transfers during the incident,” up from the more than $350 million initially disclosed. Based on IP behavior patterns and on-chain analysis, she wrote that the attack method is “highly consistent with known patterns of North Korean hacker organizations” — the groups US authorities have long tied to the Lazarus apparatus. Bitget says it has identified the stolen assets, which were mostly ethereum, tron and the USDT stablecoin, with no bitcoin in the main haul; a stolen-funds tracker nevertheless shows the attacker already holding over $28.8 million in the leading cryptocurrency after conversions. “Our goal is to complete a full recovery as soon as possible,” Chen stated, adding that a specific time window will be announced once confirmed. Security analysts note North Korean crypto thieves have grown faster and more sophisticated since last year, with experts pointing to artificial-intelligence tooling that lets operators work more efficiently. The breach caps a bruising stretch for custody security: in July, attackers exploited a firmware bug in Coldcard hardware wallets to steal nearly $120 million, and this month white-hat actors pulled roughly 4,000 bitcoins — about $320 million at the time — from the federation wallet of Blockstream's Liquid sidechain, returning 85% before demanding the rest as ransom.
Security researchers' real-time flag of the unauthorized Bitget wallet transfers
https://x.com/hackenclub/status/2103216092583964978
Cold Storage Untouched as $464M Fund Backstops Users
Bitget's official incident disclosures state the compromise stayed confined to some hot and warm wallets while cold wallets were untouched, and that user account balances remain protected. The exchange says its User Protection Fund — sized at more than $464 million — exceeds the loss amount, giving it stated capacity to cover the roughly $351.6 million first reported before the figure was revised to $388 million. Withdrawals are paused while security checks run, a measure that shields the remaining treasury but leaves users temporarily unable to move funds out. Traders running leveraged positions through margin trading face an added complication when withdrawals freeze, since capital cannot be shifted to cut risk, and anyone rechecking how market and limit order types behave during a freeze should review venue-specific rules before acting. The incident joins a long lineage of exchange breaches. Mt. Gox lost about 647,000 BTC to years of unauthorized access and collapsed in 2014. Bitfinex saw 119,754 BTC drained in 2016 despite multisig controls — proof that multisig alone is no safeguard. Coincheck lost roughly 523 million XEM, about ¥58 billion, in 2018 and later compensated users around ¥46.3 billion from its own capital; Zaif lost ¥6.7 billion the same year, both via hot-wallet compromises. Binance lost 7,000 BTC in 2019 and absorbed it through its SAFU fund; KuCoin saw $281 million taken in 2020 with cold wallets intact, later recovering much of it through on-chain tracing and cooperation with other exchanges and token issuers. DMM Bitcoin's 2024 breach took 4,502.9 BTC, roughly ¥48.2 billion, after fake-recruitment malware compromised an employee endpoint and tampered with legitimate withdrawal requests. Bybit's ~$1.4-1.5 billion 2025 theft — among the largest on record — was attributed by the FBI to North Korea's TraderTraitor, with attackers targeting the cold-wallet signing process itself. The decade-long arc shows attackers shifting from stealing keys outright to subverting people, endpoints, APIs and the entire signing workflow around them. Readers tracking the market in real time can follow live spot and futures prices on Bybit.
On-Chain Trail Tightens as Root Cause Stays Open
COINOTAG's reading of the evidence: the attacker's funds are moving in the open — the public tracker already shows over $28.8 million in bitcoin after swaps from the drained ethereum and tron-based USDT, meaning conversion rather than concealment is the immediate goal. The official post-mortem so far fixes the scope (hot and warm wallets, cold storage untouched), the amount (roughly $388 million) and the attribution, but the root cause of the intrusion remains under investigation — and without it, remediation is incomplete. Bitget's stated levers are frozen withdrawals, a $464 million protection fund and a committed recovery window. Where retail attention once chased assets from Litecoin (LTC) to niche tokens, it now fixes on custody infrastructure itself; venues that recover stolen funds, as KuCoin demonstrated, are the ones that retain users — a standard our guide to the best crypto exchanges tracks closely.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


