Bitget Hacked for $351.6M: North Korea Suspected in Massive Exchange Breach
Bitget, a Seychelles-based cryptocurrency exchange, has suffered a massive hack resulting in an estimated $351.6 million loss of digital assets on September 24, 2026. The breach, which occurred at 2:31 p.m. US Eastern Time, affected parts of the exchange's hot and warm wallet infrastructure, but cold storage remained secure.
The security team detected unauthorized transfers and alerted law enforcement within minutes. Investigators suspect a North Korean-linked group, possibly Lazarus, used a compromised third-party tool to spoof transactions. The attackers did not obtain private keys for any wallets, nor forge customer withdrawal requests, but rather exploited an internal system that controls wallet signatures.
CEO Gracy Chen assured customers that their balances are accurate and that the company's reserve fund will absorb the loss. She pointed out that Bitget holds more than $464 million in its protection fund, which could cover about 76% of the loss, leaving around $112 million available. The exchange has paused all withdrawals while deposits and trading continue.
Chen ruled out an inside job and attributed the breach to a North Korean group, citing IP addresses matching VPN patterns used by the group. On-chain researcher Specter linked the fund flows to earlier thefts tied to Lazarus Group. Chen emphasized that the attribution is not yet certain and the incident is still under investigation.