Choose Rich Live
Crypto News

Bitget raises hack loss estimate to $387.5 million amid suspected North Korean breach

Bitget increased its estimated losses from a Sept. 24 wallet breach to about $387.5 million after tracing additional transfers, while CEO Gracy Chen said evidence points to North Korean hackers tricking exchange systems into approving withdrawals.

Portrait photo of Bitget CEO Gracy Chen wearing a white t-shirt against a plain background.
Image: @Cointelegraph

Crypto exchange Bitget revised the estimated loss from its Sept. 24 wallet breach to approximately $387.5 million, up from an initial figure of $351.6 million, after further on-chain tracing identified additional stolen Zcash and TRON assets. Bitget confirmed that the higher figure stemmed from the original intrusion rather than a fresh wave of unauthorized transfers, and stated that the underlying vulnerability has been identified and patched.[4][5][6][7]

According to Bitget CEO Gracy Chen, the attackers never obtained private keys. Instead, they compromised a critical backend system in the exchange's wallet infrastructure and spoofed transaction data, prompting Bitget's own authorization systems to approve the fund transfers. Cybersecurity firm SlowMist reported that malicious activity tied to the incident began on Aug. 31 before hot wallets were drained on Sept. 24. Chen and blockchain analytics firm Elliptic both tied the intrusion to North Korean hackers based on IP addresses, VPN usage, and laundering patterns, though no government has formally attributed the attack.[2][3][7][8][9]

Bitget temporarily paused withdrawals after detecting unauthorized transfers, while leaving deposits and trading active. The exchange assured users that customer balances remain secure and that its User Protection Fund, which held more than $464 million at the time of the breach, covers the losses. Bitget has enlisted Mandiant and SlowMist to assist with the investigation, established a 5% recovery bounty for voluntary freezing or recovery assistance, and tapped Bybit's LazarusBounty platform as a tracking channel.[1][4][6][7]

Key facts

  • Bitget increased its estimated breach loss to approximately $387.5 million from an initial $351.6 million after tracing additional Zcash and TRON assets.
  • Attackers compromised a backend system in Bitget's wallet infrastructure to spoof transaction data, tricking Bitget's own authorization mechanisms into approving the transfers without accessing private keys.
  • Bitget CEO Gracy Chen and analytics firm Elliptic both linked the attack to North Korean state-sponsored actors based on IP patterns, VPN infrastructure, and laundering trails.
  • SlowMist reported that malicious activity associated with the Bitget hack began on Aug. 31 before hot wallets were drained on Sept. 24.
  • Bitget stated its User Protection Fund of over $464 million covers the full loss, while user balances remain safe.
  • Bitget suspended withdrawals during the incident while keeping deposits and trading active, pledging to announce a withdrawal plan by Sept. 26 at 04:00 UTC.
  • Bitget launched a recovery bounty offering 5% of any stolen funds frozen or recovered through voluntary efforts, using Bybit's LazarusBounty portal as a core channel.

Sources · 7 sources

  1. BS

    BSCN@BSCNewsPost on X ·

    CZ stands with hacked rival Bitget @cz_binance said he expects @binance, the @BNBCHAIN ecosystem, and the community to help however they can. Bitget CEO @GracyBitget thanked him, saying every second counts when tracing stolen assets. @bitget now puts the loss at about $387.5M after adding Zcash and TRON transfers to its count, and says that its $464M+ User Protection Fund covers the incident. Chen said early evidence points to North Korean hackers.

    Open source
  2. WB

    Wu Blockchain@WuBlockchainPost on X ·

    Bitget CEO: $350M Hack Very Likely Linked to North Korea On September 24, Bitget detected unauthorized transfers from several hot wallets. Bitget CEO Gracie Chen @GracyBitget said the team identified IP addresses whose VPN usage patterns matched those associated with a specific DPRK-linked group, making a North Korea connection “very likely.” She added that the attackers did not obtain private keys for Bitget’s hot, warm or cold wallets, but instead breached the exchange’s internal system and transferred funds directly. Bitget has previously said its user protection fund exceeds $464 million, which it says is sufficient to cover the loss.

    Open source
  3. BL

    Bloomberg@businessPost on X ·

    A $357 million hack of crypto exchange Bitget on Thursday was likely carried out by North Korea-linked hackers, pushing the nation-state’s haul from digital-asset thefts above $1 billion this year, according to analytics firm Elliptic https://t.co/KS6LUR1B8Q

    Open source
  4. CR

    CryptoSlateArticle ·

    Bitget’s hack just got $36 million bigger, and now there’s a bounty on the stolen crypto Bitget has raised the estimated value of assets taken in its Sept. 24 breach to $387.5 million as exchanges and security firms mobilize to freeze and recover the stolen funds. The new estimate is up from $351.6 million after further on-chain tracing identified Zcash and TRON assets that were excluded from Bitget's initial accounting, Chief Executive Officer Gracy Chen said in a Sept. 25 update . She said the increase reflected transfers made during the original incident and that no additional unauthorized transactions had occurred. Table Showing Assets Stolen From Bitget (Source: Lookonchain) Bitget said its investigation with blockchain security firms Mandiant and SlowMist remains underway, with further forensic findings expected as investigators establish how attackers breached its systems. The exchange first detected the unauthorized transfers from some hot wallets at 18:31 UTC on Sept. 24 and suspended withdrawals while keeping deposits and trading operational. Its security team has since identified and patched the underlying vulnerability, according to the latest update. The higher loss estimate comes as Bitget shifts its response toward tracing and recovery, drawing support from other crypto exchanges, blockchain projects and security companies. Exchanges join effort to freeze stolen assets Bitget said it has already frozen some affected assets in coordination with industry partners, though it has not disclosed their value. Binance and Bybit are among the exchanges publicly supporting the recovery. Bybit's Chief Executive Officer Ben Zhou said the company would assist Bitget and update its LazarusBounty platform to track the stolen funds, returning support Bitget provided after Bybit's own $1.5 billion breach in 2025 . Bitget said it would use LazarusBounty as a main channel for its recovery campaign. Chen said exchanges, foundations and security teams had already moved to freeze some attacker-controlled assets. Bitget has also published a real-time tracing dashboard, a reporting portal and an API containing attacker addresses to allow exchanges, stablecoin issuers, bridges and other infrastructure providers to monitor the funds. The exchange paired those efforts with a new Recovery Bounty Program offering rewards tied directly to frozen or returned assets. Eligible parties whose voluntary actions freeze stolen funds can receive 5% of the amount successfully frozen. Bitget is separately offering 5% of funds successfully recovered through eligible voluntary efforts. Freezes secured before the program's announcement can also qualify. Bitget will determine eligibility and bounty amounts, while actions carried out under court orders, law enforcement requests or other compulsory legal processes are excluded. The program could make the recovery campaign increasingly dependent on whether stolen assets reach infrastructure that can block their movement. Stablecoin issuers and centralized exchanges can freeze certain assets or accounts, while native cryptocurrencies moved to self-custodied addresses can be harder to stop. Withdrawals remain the next test For customers, withdrawals remain suspended more than a day after the breach. Chen said Bitget is working to restore the service and will announce its withdrawal plan by Sept. 26 at 04:00 UTC. The company has not said withdrawals themselves will necessarily resume at that time. Its latest security update says technical teams are validating the remediated systems and completing required checks before withdrawals can safely resume. Deposits and trading remain available. Bitget previously said customer balances remained accurate and that its User Protection Fund, which held more than $464 million when the incident was disclosed, covered losses. Related Reading Bitget’s $351.6 million hack pushes September crypto losses to 2026 high The revised $387.5 million estimate narrows that headline cushion to about $76.5 million before accounting for any assets recovered from the attackers. The protection fund's role will depend partly on how much of the stolen crypto Bitget and its industry partners ultimately recover. The immediate milestone is the withdrawal announcement due Sept. 26. Beyond restoring customer access, the tracing effort will determine how much of the $387.5 million Bitget ultimately has to absorb and how much it can claw back through the exchange-wide recovery campaign. The post Bitget’s hack just got $36 million bigger, and now there’s a bounty on the stolen crypto appeared first on CryptoSlate .

    Open source
  5. WB

    Wu Blockchain@WuBlockchainPost on X ·

    Bitget Raises Confirmed Incident Amount to $387.5M, Withdrawal Resumption Plan Due by Sept. 26 Bitget CEO Gracy Chen said in a post that the security incident has been contained and that no further unauthorized asset transfers are possible. Bitget will announce its withdrawal resumption plan by 4:00 AM UTC on September 26. Chen said Bitget has confirmed that approximately $387.5 million in assets were transferred to attacker-controlled addresses, up from the initial estimate of $351.6 million. The higher figure reflects additional Zcash and TRON assets identified during tracing and does not represent new theft. Bitget has also launched a recovery bounty program offering 5% of successfully frozen or recovered funds to eligible participants who directly contribute to those efforts.

    Open source
  6. CR

    CryptoSlateArticle ·

    Swiss bank shields Bitget institutions while retail funds freeze Bitget says about $387.5 million in assets was transferred to attacker-controlled addresses during a Sept. 24 wallet breach. Its withdrawals remained suspended in notices issued through Sept. 25, even as deposits and trading continued. On the day of the breach, Sygnum announced that Bitget's institutional clients could trade against collateral held at the Swiss bank instead of placing that collateral in Bitget's wallets. The juxtaposition puts a question behind the promise of off-exchange custody: which assets sit beyond an exchange wallet breach, and what still depends on the exchange when trading or withdrawals are disrupted? Sygnum's route is for eligible institutional clients who onboard with its bank. The companies have not disclosed how many Bitget clients use it or whether any Sygnum-held collateral was connected to this incident. A breach alongside a new custody route Bitget said its systems detected unauthorized transfers at 18:31 UTC on Sept. 24. Its initial notice placed the affected funds at about $351.6 million and said the breach reached portions of its hot and warm wallet layers, while cold wallets remained secure. In a Sept. 25 update , Bitget raised the estimated assets transferred to attacker-controlled addresses to about $387.5 million after including Zcash and TRON transfers in a fuller accounting. It said the revision did not represent a fresh wave of unauthorized transfers. The exchange said it identified and remediated the underlying vulnerability and contained the incident. Mandiant and SlowMist were assisting its investigation, according to Bitget. Bitget's withdrawal notice said withdrawals were temporarily unavailable while deposits and trading stayed operational. The exchange promised to announce a withdrawal plan or status by Sept. 26 at 04:00 UTC. For a customer with an ordinary Bitget balance, a displayed balance and the ability to trade do not by themselves provide an exit while withdrawals are paused. Sygnum said Bitget's institutional clients can use its Protect service for spot and derivatives trading while pledged collateral remains in Sygnum custody in Switzerland. Bitget mirrors the balance as trading margin. The bank lists Bitcoin, Ethereum, stablecoins and US Treasuries among the eligible collateral. Its published process requires a client to onboard with Sygnum, sign a contractual framework, open a Protect portfolio, and pledge assets before receiving exchange margin. Under Sygnum's description, the collateral is held in segregated accounts off the bank's balance sheet and is bankruptcy remote under Swiss banking law. Keeping the pledged assets at the bank reduces direct custody exposure to Bitget's own wallets. It also addresses the concern that if an exchange faces financial distress, the collateral is intended to remain outside its estate. These are features of the arrangement as Sygnum describes it. The announcement is dated Sept. 24 but does not state when Bitget client access became operational, nor that the integration preceded the 18:31 UTC breach or arose in response to it, nor does it identify any Bitget client who had completed onboarding, give a Bitget-specific collateral balance, or say whether Sygnum-held assets were involved in the incident. Figures in the release for Protect's total assets and the trading-volume share of all its integrated exchanges do not measure Bitget client uptake. Related Reading Bitget’s $351.6 million hack pushes September crypto losses to 2026 high The limits of custody and a separate backstop Protect's public page advertises flexible collateral top-ups and withdrawals. It does not publish the Bitget-specific contract that would determine when pledged assets can be released, how positions are settled, or what happens to margin if Bitget pauses its withdrawal service. A trading balance mirrored at an exchange is also not the same thing as an ordinary customer's withdrawable exchange balance. Trading still depends on the exchange's order, margin, and settlement processes even when the pledged assets are held elsewhere. Segregated custody can reduce exposure to theft from Bitget-held wallets and to Bitget insolvency, as Sygnum describes. The public materials do not establish that a Protect client can instantly reclaim pledged collateral during an exchange disruption, or that an exchange's operational problems could never delay settlement. They equally do not show that any Sygnum client is blocked from its collateral in this incident. The arrangement creates an optional boundary between institutional collateral and Bitget wallet custody. Bitget’s ordinary balances faced exchange-wallet exposure, while Institutional Protect keeps pledged collateral off-exchange with Sygnum. For users holding assets on Bitget, the exchange pointed to its User Protection Fund. In its initial Sept. 24 notice, Bitget said the fund was worth more than $464 million and that the then-estimated $351.6 million incident fell within its coverage. Its public fund page lists 5,500 BTC and says users may claim for qualifying losses from platform-wide events beyond their own actions or trading behavior. Bitget reserves the right to assess and investigate claims. The dollar value of a Bitcoin-denominated fund moves with Bitcoin's price . Bitget's report for August put the fund's monthly average at $382 million and its month-end value near $432 million on the same 5,500 BTC holding. Bitget also said it froze some affected assets through work with industry partners, but its Sept. 25 update did not quantify the frozen or recovered amount. The next measurable tests are a confirmed withdrawal timetable, a firmer loss and recovery accounting, and the terms of any fund disbursement. For the custody comparison, the missing facts are Bitget-specific Protect uptake and the contract governing collateral release and settlement when the exchange is under strain. The post Swiss bank shields Bitget institutions while retail funds freeze appeared first on CryptoSlate .

    Open source
  7. UN

    UnchainedArticle ·

    Bitget Confirms It Was Tricked Into Approving Its Own $388 Million Theft Bitget said Friday that attackers moved about $387.5 million out of the exchange on Thursday, raising its first estimate of $351.6 million after it counted transfers on Zcash and TRON. It said it has found and fixed the flaw the attackers used and will announce the status of withdrawals, suspended since Thursday, by midnight ET. The attackers never needed Bitget’s private keys. CEO Gracy Chen said on X late Thursday that “the attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out.” Bitget’s own systems, in other words, signed the transfers. Mandiant and SlowMist are helping investigate. Friday’s update also lists an XRP Ledger address as one of the attacker’s. Unchained reported Thursday, minutes before Bitget’s first estimate, that XRP wallets labeled as Bitget’s had sent a large sum to that address, though it could not yet tie the address to the attacker. A Familiar Playbook The method resembles the $1.5 billion Bybit theft of February 2025, which was attributed to North Korea’s Lazarus Group. Attackers there tampered with the web interface of Bybit’s multisig wallet provider, so Bybit’s signers approved a transfer that looked routine. Chen said Friday that “based on IP behavioral patterns and on-chain signatures, this attack is consistent with techniques used by DPRK-linked hacker groups.” Onchain analyst Specter said the stolen XRP could be linked to funds from July’s $24 million hack of AFX, which Specter said had been attributed to TraderTraitor, a North Korean group. Where the ETH Sits Nansen traced one branch of the stolen funds until 40,000 ETH sat divided equally among four new addresses. As of 6:34 p.m. ET Friday, those four and four other wallets on Bitget’s own list of attacker addresses held about 68,300 ETH , worth roughly $184 million , Ethereum records reviewed by Unchained show. None of the eight has ever sent a transaction. Bitget said some stolen funds have been frozen, and it is offering 5% of any funds frozen or recovered to people whose voluntary efforts lead to a freeze or recovery, with Bybit’s LazarusBounty as one channel. On Thursday, Chen said Bitget’s User Protection Fund, which she put at more than $464 million , covers the full loss . The revised figure equals about 84% of that amount. Related Listen: The Chopping Block: ColdCard’s $100M RNG Hack, AI-Powered Security & Ethereum’s Staking Yield Taper *Update, Saturday, Sept. 26, 2026, 4:10 p.m. ET: Bitget said it will resume withdrawals in phases, starting with bitcoin at 4 a.m. ET on Sept. 28, followed by ether on Sept. 29, USDT on Sept. 30, and other tokens, fiat and P2P on Oct. 2. It said user balances are unaffected and its protection fund covers the loss. The post Bitget Confirms It Was Tricked Into Approving Its Own $388 Million Theft appeared first on Unchained .

    Open source
  8. MN

    Mario Nawfal@MarioNawfalPost on X ·

    🇰🇵 North Korea has now stolen more than $1 billion in crypto in 2026 alone, and at this point it looks less like hacking and more like a state business model. The latest hit was Bitget, one of the world's biggest crypto exchanges, which lost around $387.5M last week in an attack that blockchain analysts say is highly likely linked to Pyongyang. The hackers didn't even need to steal private keys. They broke into a backend system and faked internal transfer data, so the exchange's own wallets approved the withdrawals. Bitget's CEO says the attack matches techniques used by North Korean hacker groups, and blockchain firm Elliptic traced the stolen funds through the same laundering network used after the $1.5B Bybit hack in 2025. Elliptic has tracked more than 51 suspected North Korean crypto attacks this year, and most of the biggest exchange hacks in recent years have ended up with Pyongyang's name on them. For a country locked out of the global financial system by sanctions, crypto is the perfect workaround. North Korea can't sell much to the world, but it can find weak spots in crypto platforms, and the money crosses borders in minutes. U.S. officials and UN investigators have long said the proceeds help fund North Korea's nuclear weapons and ballistic missile programs. No government has formally pinned the Bitget hack on Pyongyang yet, but the pattern is getting hard to ignore. Sanctions were supposed to cut North Korea off from the world's money, but Pyongyang got creative and found a way around them. Sources: Elliptic, Decrypt, Bloomberg, Euronews / Writer: Julie

    Open source
  9. CO

    Cointelegraph@CointelegraphPost on X ·

    🚨 UPDATE: SlowMist says malicious activity tied to Bitget’s $388M hack began Aug. 31 before draining hot wallets on Sept. 24. https://t.co/7vEOfPgFC0

    Open source