Bitget Loses $351.6 Million After Attackers Manipulate Its Wallet Authorization System

Bitget lost $351.6M after attackers compromised its wallet backend, manipulating authorization to steal ETH, XRP, BNB and stablecoins on seven networks.

Bitget Loses $351.6 Million After Attackers Manipulate Its Wallet Authorization System
APT

Illustrative image generated with AI

Listen to this articleAudio edition · 9 min

Backend compromise triggered unauthorized transfers

Cryptocurrency exchange Bitget said attackers stole approximately $351.6 million after compromising a critical backend system within its wallet infrastructure.

The exchange detected the unauthorized transfers at 18:31 UTC on September 24, 2026. According to CEO Gracy Chen, the intruder manipulated transaction data so that Bitget’s authorization process approved transfers that should not have been permitted.

This was not described as a theft of private keys. Instead, the attacker appears to have compromised the systems responsible for preparing, validating, or authorizing wallet transactions. Bitget has not identified the exact backend component involved or explained which controls failed.

The initial-access vector also remains unknown. Bitget said the intrusion method was still under investigation, but that its containment measures had prevented any further unauthorized transfers.

The incident affected a limited number of exchange wallets. Bitget’s public account referred to both hot and warm wallets, while separate reporting described the affected infrastructure as hot wallets. Both accounts agree that Bitget’s cold wallets were not compromised.

Attackers moved six assets across seven networks

Chen identified the stolen assets as:

  • ETH
  • XRP
  • BNB
  • AVAX
  • USDT
  • USDC

Bitget observed related activity across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. XRP accounted for the largest loss recorded on a single blockchain.

No complete public transaction list or set of attacker-controlled wallet addresses has been released. That limits the ability of customers and independent investigators to identify all related movements from the information currently available.

The difference between the affected wallet descriptions remains unresolved. Hot wallets are normally connected to operational systems so exchanges can process withdrawals rapidly. Warm wallets generally occupy an intermediate operational tier, although implementations vary between companies. Bitget has not disclosed its internal wallet architecture, balance distribution, or approval thresholds.

Cold storage remained unaffected. That distinction limits the known scope of the compromise, but it does not explain how a backend service gained enough authority to submit transaction data that downstream controls accepted.

The attack targeted trust in transaction data, not cryptographic keys

Bitget’s explanation points to a compromise of the transaction authorization path. The attacker allegedly falsified transaction information before it reached the approval stage, causing the system to authorize transfers under false premises.

This model differs from an attacker obtaining a private key and signing transactions independently. A backend compromise can exploit the trust relationships between internal services, policy engines, wallet-management platforms, and signing systems even when the underlying keys remain protected.

However, the available details do not establish whether the attacker altered recipient addresses, asset amounts, network information, approval records, or another transaction field. It is also unknown whether the affected process was automated or required human approval.

Bitget has not disclosed:

  • How the attacker first entered its environment.
  • Which backend service was compromised.
  • Whether stolen employee or service credentials were used.
  • How long the intruder had access before the transfers.
  • Whether security logs or internal records were altered.
  • Which technical changes were made after containment.
  • Any network, host, or wallet indicators that customers can inspect.

Until the investigation answers those questions, the incident should not be interpreted as a failure of a particular blockchain or digital-signature algorithm. The known failure occurred inside the exchange’s wallet infrastructure and authorization workflow.

Withdrawals paused while investigators trace the funds

Bitget temporarily suspended withdrawals as a precaution and began a broader security review. Deposits and trading continued, while the exchange said customer account balances remained accurate.

No timetable for restoring withdrawals was disclosed. Bitget also did not explain how the $351.6 million loss would be accounted for or whether any recovery mechanism would apply if frozen assets could not be returned.

The company hired Google-owned incident response firm Mandiant and blockchain security company SlowMist to support an independent investigation. The incident was also reported to relevant authorities.

Bitget contacted the foundations associated with the affected blockchains. Chen said some had confirmed freezes against addresses linked to the attacker, potentially restricting the movement of assets under their control. The number of frozen addresses and the value contained in them are not known.

Freezing is not equally available across all assets. Centralized stablecoin issuers and certain ecosystem organizations may be able to restrict specific tokens or coordinate countermeasures, while native cryptocurrency transfers generally cannot simply be reversed. Bitget has not provided an estimate of how much money might ultimately be recoverable.

The company’s self-custodial product, Bitget Wallet, was reported unaffected. It operates on infrastructure separate from the centralized exchange, meaning the disclosed backend breach does not currently extend to that product.

Customers should verify that their displayed balances remain correct and monitor Bitget’s official communications for withdrawal updates. There are no public technical indicators that users can presently search for on their own devices.

North Korean involvement is suspected but not established

Bitget said the operation was highly consistent with known North Korean threat-actor behavior. Its assessment was based on IP activity and analysis of blockchain transactions.

The company has not published the evidence behind that conclusion. Chen also did not attribute the theft to a named North Korean group, making this a behavioral assessment rather than a confirmed attribution.

The distinction is significant. IP addresses can be routed through compromised infrastructure, proxies, or commercial services, while blockchain laundering patterns may be copied by unrelated criminals. Strong attribution normally depends on multiple evidence streams, including malware, infrastructure reuse, operator mistakes, access methods, and intelligence unavailable in public reporting.

The incident follows another North Korea-linked operation targeting an India-based IT services company. In that case, attackers used fraudulent Terraform job tests to reach developer systems, but no evidence currently connects that intrusion to the Bitget theft.

TraderTraitor, a North Korea-linked cluster, has previously been associated with major cryptocurrency operations, including the roughly $1.5 billion Bybit theft and a Kelp DAO LayerZero bridge incident valued in different reports at $290 million or $292 million. The FBI attributed the Bybit theft, which occurred in February 2025, to North Korea.

Those precedents provide context, not proof. Neither Bitget nor the investigators have identified TraderTraitor—or any other specific North Korean group—as responsible for this compromise.

Critical questions remain unanswered

The immediate containment appears to have stopped further unauthorized transfers, but the central technical questions are still open. Investigators must determine how the attacker reached the backend, how transaction data could be falsified, and why the authorization process accepted it.

Bitget also needs to clarify whether warm wallets were involved, disclose the scale of successful asset freezes, and explain what controls now separate transaction creation from approval and signing.

For customers, the most consequential facts are narrower: account balances were reported as accurate, trading and deposits continued, withdrawals were temporarily suspended, and Bitget Wallet was unaffected. Cold wallets were also outside the known compromise.

The theft nevertheless demonstrates that protected private keys do not, by themselves, secure an exchange. If an attacker can control the data presented to a trusted authorization system, the resulting signatures may remain cryptographically valid while approving entirely fraudulent transfers.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →