Skip to content
Back to Guavy Wire
Crypto

$351M Bitget Hack: North Korean Group Suspected in Backend Breach

Instruments
ETH XRP ARB
Share

A $351.6 million breach at Bitget has frozen withdrawals and left users on edge as the exchange investigates.

The hack, which occurred on September 24, involved attackers moving funds from hot and warm wallets without accessing private keys or cold storage. The stolen assets were spread across seven chains, including Ethereum, XRP Ledger, and Arbitrum.

According to blockchain data, the first unauthorized transfer was made just minutes after detection, with attackers pushing forged requests through Bitget's backend systems. Some chain foundations have since frozen hacker addresses, and CEO Gracy Chen has confirmed that some stolen funds have been recovered, although no amount was specified.

The breach is attributed to a highly consistent pattern of North Korean hacker groups, based on IP behavior and on-chain analysis. Chen noted that private keys for all three wallet tiers remained safe, but the controls in front of them failed. The User Protection Fund, valued at over $464 million, covers the full loss.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc