Bitget Hacked: $352M Theft Largest Crypto Heist 2026

BItget Hacked
BItget Hacked

HOC Shorts

Crypto exchange Bitget hacked – Confirmed a massive security breach resulting in the theft of $351.6 million from its hot and warm wallet infrastructure.

  • The Vector: Attackers compromised a critical backend system tied to wallet operations to spoof transaction history and trigger legitimate internal authorization signatures—bypassing private key theft entirely.
  • Primary Suspect: Bitget CEO Gracy Chen stated early findings and VPN IP address patterns link the attack to a North Korean state-sponsored threat actor (likely the Lazarus Group).
  • Financial Mitigation: Bitget confirmed user balances will be covered 100% by its $464 million User Protection Fund.
  • Platform Status: Hot/warm outflows have been contained, cold storage remains untouched, and while trading/deposits continue normally, withdrawals remain temporarily suspended.

Centralized cryptocurrency exchange Bitget reported a major security breach involving unauthorized transfers totaling $351.6 million. The incident, initially flagged by on-chain tracking group Arkham Intelligence on September 24, represents the largest single point-of-failure exploit recorded across the cryptocurrency sector in 2026.

In a live update, Bitget Chief Executive Officer Gracy Chen confirmed that while hot and warm wallet infrastructure sustained heavy losses, the exchange’s cold storage facilities were untouched, and all affected customer funds would be made whole via internal reserves.

Bitget Hacked – Technical vectors | Infographic

Bitget hacked technical vectors
Bitget hacked technical vectors

1. No Private Key Compromise: Unlike traditional hot wallet heists where cryptographic private keys are stolen, Bitget stated its private keys remained secure. Instead, the attackers breached a critical backend operational server.
2. Spoofed Authorization Data: By gaining administrative control over the backend server, the threat actors forged transaction data directly. This tricked Bitget’s automated wallet signing system into authorizing massive outflow transfers as if they were valid platform movements.
3. Multi-Asset On-Chain Drainage: The attackers extracted $157.4 million in XRP, followed by large positions in ETH, USDT, USDC, and AVAX.
4. Immediate Stablecoin Conversion: To prevent issuers (Tether and Circle) from executing centralized smart contract freeze functions, the attackers immediately swapped stablecoin and altcoin balances into Ethereum (ETH) across multiple decentralized exchanges and cross-chain bridges.

Gracy Chen @Bitget CEO on X stated:

“Here is what we can confirm at this stage: On the attack: Our security team has made initial progress in tracing the source. The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out. Private key compromise has been ruled out — this excludes the more severe risk scenarios. Loss containment is confirmed. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation. A full technical report will follow once confirmed. On withdrawal restoration: Multiple technical teams are working in parallel on system remediation and security hardening. Withdrawal restoration is being prepared in parallel. We will announce a timeline as soon as one is confirmed — we will not commit to a window we cannot guarantee.”

Attribution & The North Korea Link

During a Q&A session following the breach, CEO Gracy Chen dismissed speculation of an insider threat, pointing to external nation-state involvement.

  • IP & VPN Signatures: Investigators traced the initial breach connections to specific VPN configurations previously utilized by Democratic People’s Republic of Korea (DPRK) cyber-espionage units, specifically the Lazarus Group.
  • On-Chain Footprints: Independent blockchain analysts flagged that stolen XRP laundering pathways matched wallet infrastructure leveraged during the $24 million AFX attack in July 2026—a campaign attributed to the North Korean threat actor cluster TraderTraitor.

Platform Response & User Protection

Category Status / Action Taken
System Containment Backend breach patched; unauthorized hot wallet outflows stopped.
User Fund Compensation 100% covered via Bitget’s $464M User Protection Fund + $1B corporate reserves.
Current Platform Operations Spot & Derivatives Trading: ONLINE / Deposits: ONLINE / Withdrawals: SUSPENDED.
Self-Custody Bitget Wallet Fully independent; zero impact reported on self-custodial user assets.

Bitget stated it is working alongside security firms (including CertiK and Bybit’s security response team) and global law enforcement to track, tag, and black-list the hacker’s receiving addresses. A full technical incident report is slated for release within 24 hours.

Join Our Club

Enter your Email address to receive notifications | Join over Million Followers

Previous Article
ChatGPT and Cybersecurity

ChatGPT and Cybersecurity: Risks, Uses, and Misuses

Related Posts