Inside the $351.6 Million Bitget Exchange Heist
On September 24, 2026, the cryptocurrency sector suffered one of its most severe security breaches of the year when the centralized exchange Bitget lost approximately $351.6 million to a highly sophisticated cyberattack. Suspected North Korean state-sponsored threat actors successfully bypassed the exchange’s internal authorization controls, exfiltrating a staggering amount of digital assets from the platform’s hot and warm wallets while leaving the broader crypto community on high alert.
The Anatomy of the Breach
At 18:31 UTC, Bitget’s automated security systems flagged highly anomalous, unauthorized outbound transfers. Interestingly, this was not a traditional private key compromise. Bitget CEO Gracy Chen confirmed that the attackers infiltrated a critical backend system within the exchange’s wallet infrastructure. By hijacking this internal system, the threat actors managed to spoof transaction data, essentially feeding forged transfer requests directly into Bitget’s proprietary authorization process. The exchange’s system, trusting the spoofed internal signals, approved the illicit transfers and initiated the draining of the hot wallets.
The Stolen Assets
The scale of the theft was massive, spanning nine distinct digital assets across multiple blockchains, including Ethereum, Arbitrum, Avalanche, and the XRP Ledger. Blockchain security firm SlowMist and on-chain tracker Lookonchain reported that the stolen funds included:
-
102.93 million XRP: Valued at roughly $157.5 million, marking the largest single asset loss.
-
31,890 ETH: Worth approximately $85.8 million.
-
Stablecoins: Roughly $75.5 million distributed across USDT and USDC.
The attacker immediately began converting the Ethereum Virtual Machine (EVM)-chain assets into ETH across 11 EVM addresses, 7 XRP Ledger addresses, and 1 Tron address—a classic laundering strategy used to obscure the money trail.
Attribution and Mitigation
While formal attribution takes time, early IP behavior patterns and on-chain analysis highly align with the modus operandi of North Korean hacker syndicates. These state-sponsored groups, such as the TraderTraitor group, have a long history of targeting bridges and centralized exchanges to fund state operations.
To contain the fallout, Bitget immediately suspended all withdrawals pending a comprehensive security review alongside third-party investigators Mandiant and SlowMist. Fortunately, Bitget’s cold wallets, which house the overwhelming majority of user funds, remained fully secure. The exchange announced that the entire $351.6 million loss would be covered by the Bitget User Protection Fund, a reserve holding 5,500 BTC (worth roughly $464 million), ensuring that user balances remain whole.
