Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
    3D Liquid Network logo with a hooded hacker shadow and computer code overlays in the background
    Liquid Network Exploit Explained: Unbacked L-BTC and the $320M Peg-Out
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Bitget Hacked for $351.6M: Withdrawals Frozen as CEO Points to North Korea

A backend breach sent assets across 19 attacker transfers, while Bitget’s $464 million protection fund faces a potential $351.6 million payout.

Written By Dishita Malvania
Published 1 hour ago·Updated 19 minutes ago
Make The Crypto Times preferred on GoogleGoogle
Bitget Hacked for $351.6M: Withdrawals Frozen as CEO Points to North Korea

Bitget, the Seychelles-based cryptocurrency exchange, has confirmed that attackers moved an estimated $351.6 million in digital assets out of parts of its hot and warm wallet infrastructure on September 24, 2026. If the figure holds, it would be the largest reported exchange hack of 2026 so far.

The exchange has paused all withdrawals while deposits and trading continue, and Chief Executive Officer (CEO) Gracy Chen said customer balances are accurate and the company’s reserve fund will absorb the loss.

AI Summary
Show
CEO Gracy Chen announced the $351.6 million hack, halted withdrawals, and pledged the protection fund to cover losses.
Bitget’s security team detected the breach in hot and warm wallets, flagged addresses, and alerted law enforcement.
Investigators suspect a North Korean‑linked group, possibly Lazarus, used a compromised third‑party tool to spoof transactions.

What Bitget Has Confirmed

Bitget’s security systems detected unauthorized transfers at 18:31 Coordinated Universal Time (UTC) on September 24, which was 2:31 p.m. US Eastern Time, according to the security notice Chen posted on X at 21:30 UTC. The same statement went live on Bitget’s support center at the same time.

Bitget stores customer assets across three wallet tiers. Hot wallets stay connected to the internet so the exchange can process withdrawals quickly. Warm wallets sit in the middle, holding reserves that refill hot wallets under tighter controls. Cold wallets are kept offline and hold the bulk of assets. Chen said the breach was limited to portions of the hot and warm layers and that cold storage remained secure.

According to the notice, Bitget activated its emergency response within minutes, flagged the receiving addresses, and notified law enforcement and on-chain security firms. The company promised hourly updates and a full report covering the root cause and corrective actions within 24 hours.

“Every dollar and every decision will be accounted for, transparently and in full,” Chen wrote.

How the Attackers Got In

In her first notice, Chen declined to speculate on the attack vector. At 00:43 UTC on September 25, she posted a second update saying the security team had traced the breach to a critical backend system inside the wallet infrastructure. Attackers used that system to spoof transaction data, which then passed through Bitget’s standard authorization process.

Chen ruled out a private key compromise. She said loss containment was complete and no further unauthorized transfers were possible, while the exact intrusion method remained under review.

In a later livestream, Chen added that the attackers did not forge customer withdrawal requests and did not obtain private keys for any cold, hot or warm wallet. In practical terms, the cryptography protecting the wallets held, but the internal system that tells those wallets what to sign was hijacked. This makes the incident closer to a signing pipeline breach than a classic key theft.

Chinese-language accounts of the livestream reported that Chen described the entry point as a compromised third-party tool used in Bitget’s operations. Bitget’s written statements have not confirmed that detail.

What Was Taken

The first public estimates understated the loss. On-chain monitors initially counted between $170 million and $192 million leaving Bitget-labeled wallets. Analytics firm Bubblemaps tracked 15 transfers worth about $192 million across seven assets, with Ether (ETH) making up 44.4% of that early slice.

The gap closed once the XRP Ledger was counted. SlowMist’s tracking tool MistTrack tagged seven XRP Ledger addresses holding about 102,926,478 XRP, a leg that most Ethereum-focused dashboards missed in the first hours. On-chain analytics account Lookonchain then published a nine-asset breakdown totaling about $356.86 million at the prices it used, close to Bitget’s internal figure.

AssetAmountValue (Lookonchain)
XRP102,926,478$157.48 million
Ether (ETH)31,890$85.75 million
Tether (USDT)34,751,168$34.75 million
USD Coin (USDC)21,056,725$21.06 million
USDT019,668,852$19.67 million
Tether Gold (XAUt)3,000$12.82 million
BNB12,719$9.88 million
Avalanche (AVAX)821,012$8.38 million
Tron (TRX)20,593,377$7.07 million

USDT0 is a cross-chain version of Tether’s USDT stablecoin, and XAUt is a token backed by physical gold. Chen said the affected networks included Ethereum, the XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum.

During the livestream, Chen said Bitget’s official count remained $351.6 million across 19 attacker transfers, all from hot and warm wallets. She said the stolen stablecoins and related tokens were converted into roughly $170 million worth of ETH. Stablecoin issuers such as Tether and Circle can freeze tokens on their own networks, while ETH has no central issuer that can block it. Blockchain explorer Etherscan has labeled at least one receiving cluster “Bitget Exploiter 1.”

Who Bitget Believes Is Behind It

Chen told a live question-and-answer session that investigators found IP addresses matching virtual private network (VPN) patterns used by a group from the Democratic People’s Republic of Korea (DPRK), or North Korea, and that the activity resembled earlier North Korean operations. She said Bitget does not believe the breach was an inside job and stressed that the attribution is not yet certain.

On-chain researcher Specter separately argued that the fund flows overlap with an earlier theft cluster tied to the Lazarus Group, the North Korean state-linked hacking unit blamed for a string of major crypto thefts, including the February 2025 Bybit hack. Bitget has not confirmed that link. For now, the North Korea attribution stands as a preliminary assessment from the CEO rather than a completed forensic finding.

Can the Protection Fund Cover the Loss?

Bitget launched its User Protection Fund in 2022 with a $300 million commitment. The fund is a corporate reserve meant to compensate users after extreme events such as hacks. Chen said it held more than $464 million at the time of the notice.

A $351.6 million payout would consume about 76% of that pool and leave roughly $112 million, assuming the full balance is liquid and available. Chen also said Bitget holds more than $1 billion in its own capital, and pointed to Bybit’s decision to absorb a loss of about $1.5 billion in February 2025 and continue operating.

Bitget’s August 2026 protection fund report showed an average valuation of about $382 million, a high of $441.5 million, a low of $345.3 million, and 5,500 Bitcoin (BTC) inside the pool. Because much of the fund is held in BTC, its dollar value moves with the Bitcoin price.

The fund is separate from Bitget’s Proof of Reserves (PoR), a periodic snapshot showing whether an exchange’s holdings exceed customer balances. Bitget’s September 2026 PoR update, Issue No. 46, reported a 135% aggregate reserve ratio and expanded coverage from four assets to 19. PoR measures solvency at a single point in time. The hack tests the protection fund, not the reserve ratio.

Two limits apply. The protection fund has not been publicly audited in the way a bank deposit insurance scheme would be. And coverage of the loss does not reopen withdrawals. Users can see correct balances but still can’t move funds until Bitget completes its backend review.

What Others Are Saying

Aneirin Flynn, CEO of cybersecurity firm FailSafe, said the breach destroys the illusion that major exchanges have solved hot-wallet security, in comments carried by Bloomberg. He added that even with the loss covered, a breach of this size damages institutional confidence in crypto infrastructure.

Xie Jiayin, Bitget’s head of Greater China, said the exchange has hired a third-party security team to run an independent forensic investigation. Several teams are verifying fixes, confirming the attack path and supporting law enforcement, and withdrawals will resume once all potential risks are removed, he said. Bitget Wallet, the company’s separate self-custody wallet app, said it was not affected by the exchange incident.

A Costly Month for Crypto Security

The Bitget breach adds to a heavy September. Earlier this month, about $320 million in Bitcoin was drained from a wallet used by the Liquid Network, according to the same Bloomberg report. Industry tallies show that adding Bitget’s loss pushes September’s reported crypto thefts above $684 million, surpassing April’s $646.9 million, which was driven by the Drift and KelpDAO exploits.

Bitget was already managing fallout from another incident this week, having paused FET deposits after the SingularityNET bridge exploit widened. The exchange ranked as the sixth-largest by trading volume on CoinGecko near the time of the notice, handling more than $1.1 billion in daily trades. It is also winding down its services in Japan by December 31.

The incident remains far smaller than the Bybit theft of February 2025, still the largest exchange hack on record.

Where Things Stand for Users

At the time of writing, Bitget reports the following status:

  • Account balances: accurate, according to Bitget
  • Deposits: open
  • Spot and derivatives trading: open
  • Withdrawals: paused
  • Cold wallets: not affected, according to Bitget
  • Law enforcement and on-chain firms: notified
  • Full incident report: due before about 21:30 UTC on September 25

Chen said withdrawals will stay closed until the compromised backend path is fully secured, since reopening early could expose the exchange to a second loss. She indicated restoration could take hours or days but not weeks.

Users should treat only the @GracyBitget and @bitget accounts on X as official channels and ignore any unofficial “emergency withdrawal” links, which are a common phishing tactic after major hacks.

What Comes Next

Three developments will shape how this incident is judged: the confirmed reopening time for withdrawals, an asset-by-asset account of any recovered or frozen funds, and whether independent security firms corroborate the North Korea attribution. The written root cause report will be the first document to answer those questions on the record.

This is a developing story. The Crypto Times will update this report as Bitget publishes its incident findings and as withdrawals, recoveries, and attribution are confirmed.

Also Read: Duelbits Hit by Suspected $4.3M Crypto Hack as Funds Shift to ETH

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:BitGetCrypto HackNorth Korea
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Exterior facade of the Federal Reserve Eccles Building in Washington, D.C.
Federal Reserve Proposes Stablecoin Rules Under GENIUS Act
IBM and Swift corporate logos side-by-side on a dark slate background.
IBM Expands Digital Asset Haven With Swift Ledger Connectivity
Silver Ethereum (ETH) token standing upright beside stacked coins in front of a market price chart.
Ethereum Leads $46B Tokenized RWA Market With 48.4% Share
Official seal of the Commodity Futures Trading Commission (CFTC) mounted on a red brick wall.
CFTC Updates Crypto Guidance as Tokenized Assets Hit $46B
3D metallic "RWA" abbreviation letters resting in front of an illuminated city skyline at sunset.
RWA Perp Volume Hits $117B as On-chain Share Reaches 86%

Find Us on Socials

You may also like

Handcuffed individual in a courtroom setting with a gavel and a Coinbase sign in the background.

Brooklyn Man Sentenced to 12 Years for $16M Coinbase Phishing Scheme

Electroneum and BNB Chain cryptocurrency tokens side-by-side on a reflective surface.

Meter Passport Exploit Reportedly Mints $2.3 Million in Unbacked MTRG

Duelbits corporate logo mounted on a dark interior wall.

Duelbits Hit by Suspected $4.3M Crypto Hack as Funds Shift to ETH

Smartphone displaying Payy app logo on a bright lime-green screen held in hand

$1.83 Million in USDC Leaves Payy Network’s Ethereum Rollup Contract

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information