Bitget Loses $351.6 Million to Suspected North Korean Hackers After Backend Compromise; Exchange Suspends Withdrawals

Bitget Loses $351.6 Million to Suspected North Korean Hackers After Backend Compromise; Exchange Suspends Withdrawals

Bitget Loses $351.6 Million to Suspected North Korean Hackers After Backend Compromise; Exchange Suspends Withdrawals

Cryptocurrency exchange Bitget says suspected North Korean hackers stole $351.6 million from its hot and warm wallets after compromising a critical backend system in the company's wallet infrastructure. "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," the exchange said. Cold wallets and the overwhelming majority of platform assets were not affected, customer balances remain accurate, and deposits and trading continue — but withdrawals are temporarily suspended while a comprehensive security review runs.

Bitget CEO Gracy Chen said the stolen assets include ETH, XRP, BNB, AVAX, USDT and USDC, spread across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base — with XRP accounting for the largest loss on a single chain. "The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out," Chen said. "No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation." Private keys were not compromised, and Bitget has brought in Mandiant and SlowMist for a third-party investigation. Some affected chain foundations have already frozen attacker wallet addresses.

Attribution rests on behavior so far, not a named group: "Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations," Chen said. North Korean operators have stolen billions from the crypto industry — the FBI blamed them for the $1.5 billion Bybit heist in February 2025, and the TraderTraitor crew is also linked to the $292 million KelpDAO theft. A week before the Bitget incident, SentinelOne attributed a TraderTraitor attack on an India-based IT services company.

Bitget, founded in 2018, runs a centralized spot and derivatives exchange; its self-custodial Bitget Wallet runs on separate infrastructure and was not affected. The company says the incident has been reported to the relevant authorities.

What Should You Do?

  1. If you operate an exchange or custodial platform: re-examine how your transaction-authorization flow validates the data source, not just signatures — a spoofed-but-validly-signed transfer passes every key check on the way out.
  2. Monitor withdrawal velocity and destination clustering in real time. Bitget caught this at 18:31 UTC because security systems flagged abnormal transfers, not because a key leaked. Detection on the money path is what limits the blast radius.
  3. If you hold funds on an exchange: remember that custody means your assets live inside someone else's authorization boundary. Assess platform proof-of-reserves, insurance and incident transparency before parking large balances.
  4. Move fast on chain-level freezing. Bitget's outreach to foundations got some attacker addresses frozen — coordination with chains is now part of incident response, and hours matter.

The WAF Angle

Nothing in this breach broke a WAF — and that is precisely the lesson. The attacker entered through a compromised backend system, presented spoofed transaction data to an authorization process that trusted its inputs, and the funds moved with valid signatures. Perimeter defense protects the front door; what got Bitget was a poisoned command channel between two systems that already trusted each other. The fixes live behind the WAF: validate transaction payloads end-to-end between backend and signer, treat the transaction-authorization path as a crown-jewel API with its own anomaly detection, and require multi-party or human signoff for high-value transfers. If your threat model stops at the HTTP perimeter, an attacker with a single backend foothold already owns everything the WAF was guarding.

Sources