Bitget says hackers drained $351.6 million from its hot wallets in 19 transfers and points to North Korea — the second major exchange in 19 months to be emptied without a single private key being stolen
The exchange detected the outflows at 18:31 UTC on Thursday, froze withdrawals and said its $464 million protection fund covers the loss in full. What it has not yet explained is how an attacker reached the backend system that tells Bitget's own signers which transfers to approve. That is the same category of failure that cost Bybit $1.5 billion in February 2025.

The most important sentence Bitget chief executive Gracy Chen said on Friday was not the one about North Korea. It was this: "Private key compromise has been ruled out." On its face that is reassurance. Read against the last two years of exchange hacks, it is the opposite. It means the attackers never needed the keys, because they found a way to make Bitget's own signing process hand over the money.
The numbers, as the exchange has stated them: about $351.6 million in digital assets moved out of its hot and warm wallets in 19 unauthorised transfers, detected at 18:31 UTC on Thursday. The assets included ether, XRP, the stablecoins USDT and USDC, Avalanche's AVAX and BNB, spread across five networks: Ethereum, the XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum. Early on-chain estimates had put the outflow at roughly $183 million; Bitget said those analyses had not captured every affected chain. Cold wallets, the offline storage where the bulk of customer funds sit, were not touched.
What the attacker actually did
Bitget's security team described the intrusion in one dense sentence: the attacker breached a critical backend wallet system, used it to spoof transfer information, and triggered the exchange's authorisation-signing process. Chen said the specific method used to get into that system is still under technical investigation, and that the breach has been contained.
To see why that description matters, it helps to know how a large exchange moves money. Customer deposits are pooled. A small fraction is kept in hot wallets, connected to the internet and used to pay out withdrawals in real time; a middle tier of warm wallets sits between the hot layer and cold storage. Every outgoing transfer from those wallets has to be signed with a private key, and at a well-run exchange the signing is not done by one person or one machine. It is done by an automated pipeline that receives a request, checks it against rules, and passes it to signers who approve what they are shown.
The weakness in that design is the phrase "what they are shown." If an attacker can compromise the system that generates the transfer requests, the signers approve a legitimate-looking instruction that has already been altered: the destination address is the attacker's, the amount is whatever the attacker chose, and the signature is genuine. No key is stolen. The lock works perfectly. It has simply been asked to open the wrong door 19 times.
The Bybit precedent
That is, in its essentials, what happened to Bybit on February 21, 2025, in what remains the largest theft in the history of the industry. About $1.5 billion in ether left a Bybit cold wallet during a routine transfer to a hot wallet. The FBI attributed the theft to North Korea's Lazarus Group, which it tracks under the name TraderTraitor. The entry point was not Bybit's keys but a developer machine at Safe, the provider of the multi-signature wallet software Bybit used; the attackers used it to serve Bybit's signers a doctored transaction that looked routine on screen. Bybit's signers approved it. The money was gone within minutes and dispersed across thousands of addresses within days.
Bitget was one of the exchanges that stepped in to help Bybit that week, lending ether to keep withdrawals flowing. On Friday the favour was returned. Bybit chief executive Ben Zhou said his team was standing by to assist and that Bybit was updating its LazarusBounty platform, built after its own hack to crowdsource the tracing of stolen funds, to track the Bitget outflows.
Private key compromise has been ruled out.
Chen made the attribution to North Korea carefully, and it should be read carefully. She said investigators had identified internet protocol addresses linked to VPN services previously used by a North Korean hacking group, and that the pattern of the attack resembled earlier operations attributed to the country. That is circumstantial: VPN infrastructure is shared and reused, and "pattern" is a judgment. The FBI's attribution of the Bybit theft came within days of the event, with on-chain evidence. Bitget's is a day old and preliminary, and the company has said so.
Why North Korea is the default suspect
The default exists because of the base rate. According to blockchain analytics firm Chainalysis, hackers linked to North Korea stole about $2.02 billion in cryptocurrency in 2025, a 51 per cent increase on the year before, bringing the regime's estimated all-time haul to $6.75 billion. Chainalysis counted $2.17 billion stolen across the whole industry in the first half of 2025, most of it the Bybit theft. North Korean operators are not the only thieves in the sector, but for thefts of this size, from centralised exchanges, targeting the signing layer, they are the only group with a documented track record.
The method has a signature too. Lazarus operations against exchanges have tended not to break cryptography. They break people and workflows: a developer's laptop, a contractor's credentials, a job offer carrying malware, a supplier whose software sits inside the target's approval chain. The Bybit theft ran through a supplier. Bitget has not said whether its backend wallet system was reached through a supplier, an employee or a software flaw, and that answer will determine whether the rest of the industry has the same hole. Bitget's own description, a backend system that generates transfer information for the signing pipeline, fits the pattern closely enough that security teams at rival exchanges will be assuming the worst until told otherwise.
What customers get, and what they wait for
Bitget's position is that no customer will lose money. The exchange says balances are accurate and that the loss is fully covered by its User Protection Fund, which it values at more than $464 million. The fund, launched in 2022, is a pool of the exchange's own assets held to backstop exactly this kind of event; Bitget's own monthly reports put its average value at about $382 million in August, which means the fund's headroom over a $351.6 million loss is real but not large, and depends on the market price of the assets it holds.
Withdrawals are suspended while the affected systems are repaired and reinforced. Deposits and trading continue. Chen declined to give a firm timetable but said withdrawals could return within hours or days and "shouldn't take weeks." Bybit kept withdrawals open throughout its own hack and said it had cleared the backlog within about 12 hours, a comparison Bitget's users will be making.
The suspension is the part that tests the reassurance. An exchange that can honour every balance but cannot let customers leave is asking them to take its solvency on trust for as long as the freeze lasts. The Bybit episode showed that trust can hold if the exchange is transparent and the freeze is short. It also showed the alternative: FTX in 2022 paused withdrawals and never resumed them. Bitget is not FTX, and its protection fund is verifiable on-chain, but the length of the freeze is now the number that matters. Every hour it lasts is an hour in which the exchange's word is the only collateral its customers hold.
The counter-argument
There is a reading of this in which Bitget's response is a model. The outflows were detected the same afternoon, withdrawals were frozen before more could leave, the receiving addresses were flagged to other exchanges and blockchain security firms, law enforcement was contacted, the chief executive went on a livestream within hours, and the loss is covered without touching customer funds. Compared with the exchange failures of 2022, in which customers learned of holes in the balance sheet from court filings, this is what a mature industry response looks like.
That reading is fair as far as it goes. It does not answer the question that the Bybit hack posed and that the industry has now been asked twice: if the keys are safe and the signers are honest, why can an attacker still get the money? Both incidents point at the same place, the software between the request and the signature, and there is no protection fund for a design flaw.
The durable point is that "private key compromise has been ruled out" has become the sentence exchanges say after the money is gone. In February 2025 it was true of Bybit and $1.5 billion left anyway. On Thursday it was true of Bitget and $351.6 million left anyway. The keys were never the target. The approval was.
This report is based on statements by Bitget and its chief executive Gracy Chen on X and as reported by CNBC on Friday; the FBI's February 2025 public attribution of the Bybit theft; Bybit's own account of that incident; and figures published by Chainalysis in its 2025 crime reports. Bitget's attribution to North Korea is preliminary and the exchange has said the intrusion method is still under investigation. The size of the loss, the composition of the protection fund and the timing of the withdrawal freeze are as stated by the company and have not been independently audited.
