Bitget says a breach of a key back-end wallet component allowed an attacker to forge transaction data and move approximately $351.6 million from some of the platform’s hot and warm wallets, without obtaining private keys or accessing cold wallets. The exchange suspended withdrawals while conducting security checks and said its user protection fund, which it values at more than $464 million, is sufficient to cover the loss in full.
Chief Executive Officer Gracy Chen said the incident began at 2:31 a.m. and affected only part of Bitget’s online wallet infrastructure. In a later update, Chen said preliminary findings had ruled out private-key leakage. Instead, the attacker appears to have manipulated data submitted to the platform’s internal authorization process, enabling large outbound transfers to be approved.
The episode places attention on the systems surrounding wallet keys as well as the keys themselves. A cold wallet can remain technically secure while a compromised back-end service generates transactions that appear valid to the platform’s signing and authorization workflow.
Withdrawals halted as on-chain outflows continued
The first public signs of the breach emerged through on-chain monitoring. At 3:57 a.m., trader DCF GOD reported suspicious activity involving roughly $20 million after a newly created address used 19.67 million USDT on Arbitrum to purchase 7,111 ETH in six minutes. The purchases were executed at a premium that reached 5% above spot prices, an indication that the buyer was prioritizing speed and available liquidity.
Public transaction records cited in the alert showed the activity passing through UniswapX and 1inch Fusion. The referenced WETH/USDC liquidity pool was listed at roughly $2,870 at the time.
At 4:08 a.m., Steven, head of research at The Block, said he had identified about $174 million moving across several chains from Bitget-linked hot and cold wallet addresses to 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee. His subsequent posts described small test transactions within the same address cluster, a technique often used to check whether routes and wallet controls function before larger transfers are sent.
By 4:12 a.m., Steven said withdrawals appeared to have been paused, while about $500 million remained in wallets he was monitoring. At 4:50 a.m., funds from certain hot-wallet addresses were being consolidated at 0xffa8DB7B38579e6A2D14f9B347a9acE4d044cD54 before transfers continued toward addresses associated with the attacker.
An $8 million USDC transfer on Avalanche was recorded at 5:10 a.m., showing that outflows were continuing more than two hours after the initial breach. Chen issued Bitget’s public incident update at about 5:30 a.m., setting out the estimated loss, the withdrawal suspension and the company’s plan to provide hourly updates and a full report within 24 hours.
Funds dispersed across chains and assets
Blockchain analytics platform Bubblemaps said the attacker initially consolidated funds at the 0x770b…63Ee address before swapping and distributing assets among multiple wallets. The platform identified six subsequent recipient addresses:
- 0x469Ac1406dE92f82C0563477240a3627057425DC
- 0xe410a2E5710Ee787bcaa63f52A3943ff71F0d946
- 0xD2C2f029eFF5caCc686F24377CfdDcfc82d9F899
- 0x7c96279Ec1e888Aa56b9B836e0dB26ca48573E1C
- 0x94A43df7687A8494948Be937400e9d5D33135DA0
- 0xA6dD3F218B65E32Ccc37BE30f74884133c655545
Bubblemaps said that as of 5:33 a.m., it had tracked $191 million in stolen assets. The assets included ETH, USDT, USDC, USDT0, tokenized gold XAUT, BNB and AVAX. The gap between that early on-chain figure and Bitget’s later $351.6 million estimate reflects both the evolving nature of a live incident and the difficulty of tracing funds spread across chains, assets and intermediary wallets.
The analytics platform also identified four affected Bitget-linked addresses: 0x1AB4973a48dc892Cd9971ECE8e01DcC7688f8F23, 0xffa8DB7B38579e6A2D14f9B347a9acE4d044cD54, 0x97b9D2102A9a65A26E1EE82D59e42d1B73B68689, and 0x5bdf85216ec1e38D6458C870992A69e38e03F7Ef.
At 5:42 a.m., Bitget Wallet advised users to consider canceling existing wallet contract approvals while the review continued. Such approvals can permit smart contracts to move tokens from a connected wallet, though Bitget’s description of the exchange breach focused on its own wallet infrastructure rather than user-authorized transactions.
North Korea link remains preliminary
During a live question-and-answer session, Chen said some IP information observed during the investigation matched VPN services previously linked to a North Korea-based hacking group. She said attribution had not been finalized and that investigators had not concluded that internal staff were involved.
Chen also said the attackers did not forge user withdrawal requests and did not obtain the private keys for either hot or cold wallets. Law enforcement agencies and on-chain security firms are involved in the investigation, according to Bitget.
The company’s stated protection fund would need to absorb a substantial portion of its reported reserve if the full $351.6 million loss is confirmed. Bitget has not yet detailed the composition, custody arrangements or valuation methodology for the more than $464 million fund in its incident statements, leaving the promised full report central to assessing how reimbursement would be executed.
The breach also arrived during a month of heavy reported crypto thefts. The supplied incident account puts total reported industry losses for September above $684 million. Bitget’s BGB token fell roughly 5% shortly after the disclosure, according to the same account, while the wider crypto market had risen nearly 10% over the preceding seven days.
For Bitget users, the immediate issue is the duration and scope of the withdrawal freeze. The company says most assets were unaffected and that its cold wallets remain secure, but restoring transfers safely will require the platform to establish that the compromised authorization path has been isolated before normal wallet operations resume.
Worried about hacks and wallet safety? Learn key crypto wallet protection strategies to better secure your funds.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
