# Bitget Suffers $387.5 Million Crypto Breach in Largest Hack of the Year
## What Happened
One of the world’s largest cryptocurrency exchanges, Bitget, disclosed a massive security breach on September 24 that resulted in the loss of approximately $387.5 million in digital assets. The incident was detected at 18:31 UTC when unauthorized transfers began moving funds out of the company’s hot wallets.
Within roughly an hour, on-chain analysts had already identified approximately $183 million in stablecoins, Ethereum, and other crypto assets flowing out of wallets associated with the exchange. By the time Bitget made a public announcement hours later, the total losses had ballooned to $351.6 million. The exchange later revised the figure upward to $387.5 million.
## How the Attack Was Executed
What makes this breach particularly notable is the method used. According to CEO Gracy Chen, the attackers did not steal any private keys from cold, hot, or warm wallets. They also did not forge user withdrawal requests. Instead, the hackers gained access to a backend system within Bitget’s wallet infrastructure and manipulated transaction data in a way that tricked the exchange’s own authorization systems into approving what appeared to be routine transfers.
In essence, the attackers created convincing internal documentation that the system’s automated checks accepted at face value—similar to presenting a falsified withdrawal slip at a bank where the teller verifies the form’s legitimacy without scrutinizing the person presenting it.
## The Scale of the Theft
The stolen assets were dispersed across at least five different blockchains to addresses controlled by the attackers. The single largest component of the stolen funds was approximately 103 million XRP tokens, valued at around $157 million.
Blockchain researcher DCF GOD was among the first to identify suspicious activity, flagging a newly created wallet that spent $19.67 million in USDT0—a cross-chain variant of Tether’s stablecoin—to purchase 7,111 ETH within six minutes, paying roughly 5% above market rates through decentralized exchanges UniswapX and 1inch Fusion.
## North Korea Suspected
Gracy Chen has pointed to North Korea as the likely perpetrator, though she stopped short of confirming the attribution definitively. She stated that certain IP addresses linked to the attack matched VPN choices commonly associated with a DPRK-linked hacking group and that the on-chain behavioral signatures closely resembled techniques previously tied to North Korean state-sponsored operations.
Chen noted that she herself had been personally targeted by the same group before, losing approximately $80,000 from a personal wallet outside Bitget. The Lazarus Group, also known by the codename TraderTraitor, has been attributed to several of the largest crypto heists in history, including the February 2025 Bybit breach that resulted in a $1.4 billion loss. According to blockchain analytics firm Chainalysis, North Korean hacking operations have already accumulated more than $2 billion in stolen funds during 2025 alone.
## Customer Protection Measures
Bitget moved quickly to contain the damage. The unauthorized outflows have been halted, and no additional transfers of this nature are possible. Withdrawals were temporarily frozen as a precautionary measure, while deposits and trading activities continued without interruption.
The exchange operates a User Protection Fund with a current balance exceeding $464 million. Chen confirmed that the fund will absorb the full $387.5 million loss, meaning that customer account balances will remain unaffected despite the disappearance of the actual assets. Back in 2023, the fund held $300 million and was specifically established to cover hacks and theft so that users would not bear the financial brunt of such incidents.
## What Comes Next
Bitget has committed to publishing a comprehensive incident report that will include a root-cause analysis once its technical teams complete the system remediation process. Withdrawals are expected to remain paused until the exchange announces a plan for users wishing to move their funds. The investigation is being conducted in collaboration with Mandiant and SlowMist, two prominent cybersecurity firms.
—
## Frequently Asked Questions
**Q: What is a hot wallet, and why were hot and warm wallets targeted?**
A: A hot wallet is a cryptocurrency wallet that is connected to the internet, used for facilitating day-to-day transactions and withdrawals. Warm wallets occupy a middle ground—partially connected—used for larger but still relatively liquid holdings. Cold wallets, by contrast, are kept entirely offline. Hackers often target hot and warm wallets because these hold funds readily accessible for transactions, unlike cold wallets which require manual offline approval.
**Q: How did the attackers spoof transaction data?**
A: The attackers infiltrated a backend system within Bitget’s wallet infrastructure and altered transaction metadata in ways that the exchange’s internal authorization processes interpreted as legitimate. This allowed them to bypass the normal approval checks without needing access to the actual private keys controlling the wallets.
**Q: Will Bitget users get their money back?**
A: Yes. Bitget’s User Protection Fund, which holds more than $464 million, will cover the full $387.5 million loss. Customer account balances will remain intact, and the exchange has stated that users will not bear the financial impact of the breach.
**Q: Why is North Korea repeatedly linked to major crypto hacks?**
A: North Korea’s state-linked hacking groups, particularly the Lazarus Group and TraderTraitor, are believed to operate sophisticated cyber-espionage units that target cryptocurrency exchanges and DeFi protocols. Their activities are reportedly used to fund the country’s government programs and weapons development, making crypto theft a strategic priority for the regime.
**Q: What is a User Protection Fund?**
A: A User Protection Fund is a reserve pool maintained by a cryptocurrency exchange, funded by a portion of trading fees or other revenues. It is specifically designed to compensate users in the event of hacks, theft, or other security incidents, ensuring that customer assets are insulated from operational losses.
**Q: Are withdrawals still frozen at Bitget?**
A: As of the latest update, withdrawals remain paused. Bitget has stated that it will announce a plan for interested users once system remediation is complete, expected the following day.
—
## Conclusion
The Bitget breach underscores the persistent vulnerability of cryptocurrency exchanges to sophisticated internal attacks, even when private keys remain secure. By exploiting backend systems and spoofing transaction data, the attackers bypassed traditional security measures designed to protect digital assets. The incident highlights the critical role that User Protection Funds play in maintaining user trust and the importance of rapid incident response in minimizing damage. As investigations continue and the full scope of the attack comes to light, the broader crypto industry will be watching closely to see what security improvements Bitget and other exchanges implement in response.
Thank you for reading



