Bitget Hack Losses Reach $387.5M, Led by $157M in Stolen XRP

Bitget confirmed $387.5M in losses from a Sept. 24 wallet breach; 103M XRP worth $157M was stolen, with the CEO pointing to North Korean hackers.

(07:13 PM UTC)
4 min read
AI SummaryAI
  • Bitget losses climbed to $387.5M after the Sept. 24 hot and warm wallet breach.
  • Attackers spoofed transaction data in the wallet backend; private keys were not compromised.
  • CEO Gracy Chen cited IP addresses matching patterns tied to North Korean hackers.
  • Bitget's User Protection Fund holds over $464M and will cover the full loss.
j5wc1pnr

Inside the Wallet Backend Breach

Bitget has confirmed one of the largest crypto breaches on record: hackers made off with $387.5 million from the exchange's hot and warm wallets, and law enforcement is now investigating. The exchange's security systems flagged the first unauthorized outflows at 18:31 UTC on September 24; within roughly an hour, on-chain observers had tallied about $183 million in stablecoins, Ethereum and other assets leaving wallet addresses tagged to the exchange. When Bitget went public later that day, the figure stood at $351.6 million, and a 24-hour follow-up update from CEO Gracy Chen raised the tally to $387.5 million. Chen walked through the mechanism in a livestream and a series of posts on X. The intruders, she said, did not forge user withdrawal requests and did not obtain the private keys of the cold wallet or any hot or warm wallet. Instead, they broke into a backend system inside the exchange's wallet infrastructure and used it to spoof transaction data, tricking Bitget's own authorization flow into approving payouts that looked routine. In effect, nobody took the vault combination — they forged the paperwork, and the system signed off without asking questions. On-chain traces filled in the rest. A freshly created wallet spent $19.67 million in USDT0, a cross-chain variant of the dollar-pegged stablecoin Tether, to buy 7,111 ETH in just six minutes, paying roughly 5% above market price through the decentralized exchanges UniswapX and 1inch Fusion — a move pseudonymous researcher DCF GOD flagged while the outflows were still in progress. Assets then spread from further Bitget-tagged addresses across at least five blockchains, with the largest single component roughly 103 million XRP worth about $157 million. Chen said the outflow has since been stopped and that no further unauthorized transfers are possible; deposits, spot trading and the exchange's perpetual contract markets kept running throughout, with withdrawals alone frozen as a precaution.

Lazarus Link and the $464M Fund

North Korea is the working suspect. On-chain investigator Specter Analyst linked the operation to the Lazarus Group within hours of the first outflows, and Chen — after hosting a livestream that ran more than three hours — said the attack displays the signs of a North Korean operation. She cited IP addresses matching the VPN choices of a DPRK-linked group and on-chain signatures consistent with techniques those state-affiliated hackers have used before, while stressing that attribution is not confirmed and no technical evidence has been made public. Chen added that she has personally been targeted by the same group before, losing about $80,000 from a personal wallet outside the exchange. Lazarus, also tracked under the TraderTraitor codename, is blamed for the industry's largest heists, including Bybit's $1.4 billion theft in February 2025, which the FBI later confirmed as North Korean work; analytics firm Chainalysis puts the country's 2025 crypto haul at more than $2 billion. Cold wallets reportedly stayed secure while the hot and warm layers were hit, and Bitget's separate self-custody wallet product was untouched; several chains have frozen addresses tied to the breach. User coverage is the clearest good news: the User Protection Fund, which held $300 million in 2023 and now stands above $464 million, will absorb the full loss, so customer balances remain intact. Independent forensics by Mandiant and SlowMist are ongoing, withdrawals stay paused until the exchange sets out a plan tomorrow, and a full root-cause report has been pledged once system remediation is complete. The initial loss estimate was far lower before investigators finished reconciling the tagged wallet layers — and the incident landed, awkwardly, as Bitget celebrated its eighth birthday. Readers tracking the market in real time can follow live spot and futures prices on Bybit.

Self-Custody Debate Reopens

Our reading of the on-chain record and the exchange's own post-mortem so far: the root cause was forged transaction data fed to a functioning signing process — the authorization layer worked exactly as designed, on inputs the attacker controlled. That is a harder problem to patch than a stolen key, and remediation now rides on the Mandiant and SlowMist forensics and the pledged incident report. Coming after the Bybit breach, the raid extends the North Korean playbook and, for users, renews the self-custody argument that Bitcoin maximalism has pressed for a decade — while the cross-chain laundering routes of the kind Stargate Finance facilitates make freezing the remaining stolen funds an uphill race. Readers weighing platform risk can compare custody and proof-of-reserve practices in our Best Crypto Exchanges guide.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.