Bitget Hack Losses Climb to $387M: Here’s What Happened, and Why North Korea Is a Suspect
In brief
- Bitget confirmed a $387.5 million breach detected on September 24, after attackers spoofed transaction data to trigger legitimate-looking transfer approvals from hot and warm wallets, not by stealing private keys.
- The haul includes roughly 103 million XRP worth $157 million.
- CEO Gracy Chen says IP addresses and on-chain patterns match techniques used by North Korea's state-linked hackers.
Hackers stole roughly $387.5 million in crypto from Bitget yesterday in what is believed to be the biggest crypto hack of the year. The likely suspect is, as usual, North Korea—though that’s yet to be confirmed, and Bitget says law enforcement is now investigating.
Here’s what happened: Bitget's security systems detected unauthorized transfers moving out of some of its hot wallets at 18:31 UTC on September 24. Within about an hour, on-chain investigators had already tallied roughly $183 million in stablecoins, Ethereum, and other crypto assets sliding out of wallets tagged as belonging to the exchange.

By the time Bitget went public hours later to confirm the hack, total losses had grown to $351.6 million. The crypto exchange, one of the largest in the industry, updated that tally to $387.5 million today.
Bitget CEO Gracy Chen explained what happened in a livestream and a string of posts on X. "They did not forge user withdrawal requests, nor did they obtain our private keys of the cold wallet and any hot, warm wallet," she said. Instead, attackers broke into a backend system inside Bitget's wallet infrastructure and used it to spoof transaction data, tricking the exchange's own authorization process into approving payouts that looked routine.
In plainer terms, nobody stole the vault combination. Someone forged paperwork convincing enough that the system signed off on it without asking questions—the digital equivalent of slipping a fake withdrawal slip past a bank teller who checks the form, not the person.
Blockchain sleuths had pieces of the story before Bitget confirmed anything. Pseudonymous researcher DCF GOD flagged a freshly created wallet that spent $19.67 million in USDT0—a cross-chain version of the dollar-pegged stablecoin Tether—to buy 7,111 ETH in six minutes, paying roughly 5% above market price through decentralized exchanges UniswapX and 1inch Fusion.
Within 24 hours of the September 24 (UTC) incident: here is our further update as promised. Our investigation with Mandiant and SlowMist is ongoing — thorough forensic analysis takes more than 24 hours, and further findings will be shared as they become available. Three key…
— Gracy Chen @Bitget (@GracyBitget) September 25, 2026
More wallets tagged as Bitget's followed, sending assets across at least five blockchains to addresses the attacker controlled. The single biggest piece of the haul turned out to be roughly 103 million XRP, worth about $157 million.
Chen said the outflow has since been stopped and no further unauthorized transfers are possible. Bitget's User Protection Fund, which holds more than $464 million, will cover the full loss, she said, meaning customer account balances stay intact even though the money itself is gone.
Deposits and trading kept running throughout; withdrawals alone were frozen as a precaution.
Bitget built that protection fund years ago for exactly this potential scenario, given how common hacks unfortunately are in the industry. Back in 2023, the protection fund stood at $300 million, set aside specifically to cover hacks and theft so users wouldn't be left holding the loss.
North Korea is the usual suspect
As far as who was behind the hack, Chen has pointed a finger at Pyongyang, though carefully. "We've identified some IP addresses that match the VPN choices by a certain DPRK group," she said, adding that "the pattern looks very much like what the North Korean team did before."
She's also said the on-chain signatures line up with techniques tied to North Korean state-linked hacking groups, while stressing that the attacker's identity hasn't been confirmed and that no technical evidence has been made public.

→
Chen said she has personally been targeted by the same group before, losing about $80,000 from a personal wallet outside Bitget.
North Korea's Lazarus Group, also tracked under the codename TraderTraitor, has been blamed for the industry's biggest heists, including the Bybit lost $1.4 billion hack in February 2025, which the FBI confirmed weeks later was North Korean work. Blockchain analytics firm Chainalysis puts the country's 2025 haul at more than $2 billion.
Bitget has pledged a full incident report, including root-cause analysis, once its technical teams finish system remediation. Withdrawals remain paused until tomorrow, when the exchange will announce a plan for those interested in doing so.