North Korean hackers drain $351.6M from Bitget wallets

Bitget suffers a $351.6 million breach by suspected North Korean hackers, but its $464 million User Protection Fund ensures all customer losses are covered.

By Central
North Korean hackers drain $351.6M from Bitget wallets
Highlights
  • Suspected North Korean hackers exploited Bitget's backend system to forge transaction data and approve unauthorized withdrawals.
  • Bitget's User Protection Fund holds $464 million in BTC, fully covering the $351.6 million in stolen assets.
  • The attack, attributed to the Lazarus Group, is consistent with their known patterns and underscores risks to centralized exchanges.

The theft of $351.6 million from Bitget’s hot and warm wallets, attributed to suspected North Korean state-sponsored hackers, marks another escalation in a relentless campaign against cryptocurrency exchanges. The breach, detected Thursday evening, forced Bitget to suspend withdrawals and launch a multi-agency investigation. While the company’s cold wallets remained untouched and a $464 million User Protection Fund covers all losses, the incident raises urgent questions about the vulnerability of centralized exchange infrastructure to advanced persistent threats.

Inside the Bitget Heist: How $351.6 Million Was Drained

Bitget disclosed that the attackers exploited a critical backend system within its wallet infrastructure, using it to forge transaction data and trigger the authorization-signing process. CEO Gracy Chen explained that the compromise allowed the attackers to spoof legitimate transfer requests from a limited number of crypto wallets, enabling the movement of funds out of warm and hot storage. No further unauthorized transfers have been possible since the breach was contained, and the specific method of system intrusion remains under active investigation.

For the industry, this is not merely a financial loss — it is a stark reminder that in the digital asset space, trust is the most fragile commodity of all.

The affected chains included Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. Assets involved comprised ETH, XRP (which suffered the largest single-chain loss), BNB, AVAX, USDT, USDC, and other tokens. Notably, Bitget’s self-custodial Bitget Wallet was not impacted, as it operates on independent infrastructure. The company has also confirmed that some blockchain networks have frozen the hacker wallet addresses since the attack.

Attribution: Why Investigators Point to North Korea

According to Chen, IP behavior patterns and on-chain analysis show the attack method is “highly consistent with known patterns of North Korean hacker organizations.” This attribution places the Bitget theft alongside a string of high-profile heists linked to the Lazarus Group and its affiliates, including the record $1.5 billion Bybit cold wallet breach in February 2024, the $100 million Harmony Horizon bridge exploit, and the $620 million Axie Infinity heist. These operations are believed to fund North Korea’s weapons programs, making them a persistent geopolitical cybersecurity concern.

Bitget has reported the incident to relevant institutions and is cooperating with law enforcement agencies, on-chain security firms, and specialists from Mandiant and SlowMist. The investigation is global in scope, aiming to trace the stolen funds and identify the infrastructure used by the attackers.

What is the User Protection Fund and How Will It Cover Losses?

Bitget’s User Protection Fund currently holds 5,500 BTC, valued at approximately $464 million, which the company states will fully cover the affected $351.6 million in assets. The fund is designed to insulate customers from losses due to such security incidents. Bitget has assured users that their account balances remain accurate, and deposits and trading continue to operate normally. Withdrawals will be restored only after investigators confirm it is safe to resume normal operations.

Technical Breakdown: How the Attack Worked

The attack targeted Bitget’s hot and warm wallets — those that are internet-connected to facilitate rapid user withdrawals — rather than its cold wallets, which are offline and therefore more secure. The criminals compromised a “critical backend system within our wallet infrastructure,” according to Chen. This allowed them to spoof transaction data and trick the authorization process into signing off on illegitimate transfers.

Such an attack is distinct from typical private key theft or phishing; it involved penetrating the exchange’s internal systems to manipulate transaction validation. This sophistication aligns with the pattern seen in recent North Korean hacks, where the attackers spend months studying targets, developing custom tools, and exploiting supply chain weaknesses.

Immediate Impact on Bitget and the Crypto Market

Bitget has temporarily suspended withdrawals to prevent further exploitation and to allow forensic analysis. Despite the breach, the company emphasized that the “overwhelming majority of platform assets remain secure and unaffected.” The user protection fund provides a buffer that many exchanges lack, potentially mitigating reputational damage and customer panic. However, the incident is likely to intensify scrutiny of Bitget’s security architecture, particularly the backend wallet-service system that was compromised.

The theft comes at a time when regulators globally are tightening oversight of cryptocurrency exchanges, especially those handling large volumes of assets. The involvement of North Korean hackers will amplify calls for stricter KYC/AML protocols and mandatory security audits. For the broader crypto market, such high-profile heists continue to undermine trust in centralized custodians, accelerating the shift toward self-custody solutions and decentralized finance (DeFi) alternatives.

Evolving Threat Landscape: Why Exchanges Remain Prime Targets

North Korean hacking groups have been linked to nearly $3 billion in crypto thefts since 2017. Their methods have evolved from simple ransomware and exchange breaches to complex supply chain attacks, cross-chain bridges exploits, and now compromised backend authorization systems. The Bitget hack illustrates that even exchanges with strong cold wallet security and significant protection funds are vulnerable if attackers can inject themselves into the signing pipeline.

The Lazarus Group, in particular, has shown a capability to combine social engineering, malware, and advanced persistent threat tactics to penetrate even well-defended enterprises. The use of forged transaction data represents a new vector that many security teams may not have fully hardened against. For other exchanges, this incident serves as a critical wake-up call to audit their backend authorization processes, implement multi-factor authentication for all wallet operations, and deploy real-time anomaly detection for transaction patterns.

Practical Steps for Crypto Users Following the Bitget Breach

While Bitget has guaranteed coverage of losses, the event underscores broader risks. Users should consider the following:

  • Enable all available security features, including hardware-based two-factor authentication and whitelisting of withdrawal addresses.
  • Distribute large holdings across multiple wallets, prioritizing cold storage for long-term assets.
  • Monitor official announcements from exchanges regarding incident resolutions and timeline for restoring withdrawals.
  • Be wary of phishing attempts that may leverage the breach to steal credentials.
  • Consider using decentralized exchanges or self-custodial wallets for assets not actively traded.

The Bitget incident, while contained by a robust protection fund, exposes a fundamental asymmetry: as long as centralized exchanges hold billions in customer funds, they will face relentless, state-sponsored adversaries. The security community is now racing to develop new detection methods for this class of backend forgery attacks, but the agility of groups like Lazarus suggests the next attack is only a matter of time. For the industry, this is not merely a financial loss — it is a stark reminder that in the digital asset space, trust is the most fragile commodity of all.

Questions answered
  • How did the hackers manage to drain $351.6 million from Bitget wallets?The attackers exploited a critical backend system within Bitget's wallet infrastructure to forge transaction data and trigger the authorization-signing process, which allowed them to spoof legitimate transfer requests from a limited number of crypto wallets.
  • Why do investigators attribute the Bitget theft to North Korean hackers?IP behavior patterns and on-chain analysis show the attack method is highly consistent with known patterns of North Korean hacker organizations, such as the Lazarus Group.
  • What is the User Protection Fund and how will it cover losses?Bitget's User Protection Fund holds 5,500 BTC, valued at approximately $464 million, which will fully cover the affected $351.6 million in assets.
Share This Article