Bitget Hack Exposes $351.6m in Crypto Assets, Raises Questions Over Exchange Security
Cryptocurrency exchange Bitget has suffered a major security breach in which approximately $351.6 million in digital assets were transferred without authorisation from parts of its hot and warm...
Cryptocurrency exchange Bitget has suffered a major security breach in which approximately $351.6 million in digital assets were transferred without authorisation from parts of its hot and warm wallet infrastructure.
Bitget said its security systems detected the suspicious transfers at 18:31 UTC on September 24 and immediately activated its emergency response procedures. The exchange temporarily suspended withdrawals while keeping deposits and trading operational.
The incident has raised fresh questions about the effectiveness of cybersecurity controls at cryptocurrency exchanges, particularly the safeguards surrounding backend systems that can initiate or authorise blockchain transactions.
Bitget CEO Gracy Chen said the attackers compromised a critical backend system within the exchange’s wallet infrastructure, spoofed transaction data and triggered the company’s authorisation process to move funds.
The exchange said its investigation had so far ruled out compromise of the private keys themselves. Bitget also said its cold wallets remained secure and that no further unauthorised transfers were possible after containment measures were implemented.
For users, one of the immediate concerns is whether the breach affects the solvency or availability of customer assets. Bitget has maintained that customer balances remain accurate and that the loss is covered by its User Protection Fund, which it said contained more than $464 million at the time of the incident. Withdrawals, however, remained temporarily suspended pending security checks.
The scale of the incident subsequently appeared larger than the initial estimate. In a later update, Bitget said on-chain tracing had identified approximately $387.5 million in assets transferred to attacker-controlled addresses. The revised figure included assets on Zcash and TRON that were not included in the original $351.6 million estimate.
The distinction between the two figures is important. The initial $351.6 million estimate was based on Bitget’s preliminary assessment, while the $387.5 million figure reflects a more comprehensive classification of transactions identified during the investigation. The company said the higher figure did not represent additional unauthorised transfers.
Bitget has engaged external cybersecurity specialists, including Mandiant and SlowMist, as part of its investigation. It has also notified law-enforcement agencies and blockchain security organisations while attempting to trace and freeze affected assets.
The exchange has said that some of the stolen assets have already been frozen through cooperation with blockchain projects, exchanges and other industry participants. It has also established a recovery bounty programme aimed at encouraging efforts that result in affected funds being frozen or recovered.
Bitget has attributed the attack to methods it says are consistent with known North Korean hacking operations, based on IP behaviour and on-chain analysis. That attribution remains part of an ongoing investigation and should not be treated as an established finding of responsibility until independently confirmed by the relevant authorities.
The incident has also exposed an important distinction between Bitget Exchange and Bitget Wallet.
Bitget Wallet, the company’s self-custodial wallet product, said its infrastructure and users’ self-custodied assets were not affected. Unlike the exchange’s hot and warm wallets, which are controlled by the exchange as part of its operational infrastructure, self-custodied wallets leave control of the assets with individual users.
From a compliance and risk-management perspective, the breach illustrates that protecting private keys alone is not sufficient. The attack reportedly exploited a backend system capable of manipulating transaction information and triggering an authorisation process. That places software controls, privileged access, authentication, transaction validation and segregation of duties at the centre of the investigation.
The key questions now extend beyond how much cryptocurrency was stolen.
They include how the attackers obtained access to the backend environment, why existing controls permitted manipulated transaction information to reach the authorisation process, whether independent monitoring detected the activity quickly enough, and whether additional approval controls could have prevented the transfers.
The incident also raises questions about the governance of customer protection funds. Bitget says its more than $464 million fund is sufficient to cover the loss, but users and regulators will ultimately need clarity on the fund’s structure, liquidity, eligibility requirements and mechanism for compensating affected customers.
The exchange has pledged to publish a full incident report containing its root-cause analysis and corrective measures. That report will be important for determining whether the incident resulted from an isolated technical weakness or exposed broader deficiencies in Bitget’s security architecture and internal controls.
For the wider cryptocurrency industry, the breach is another reminder that the security of digital-asset platforms depends not only on blockchain technology but also on conventional corporate controls: access management, system segregation, independent verification, incident response, audit trails and effective oversight.
The immediate priority for Bitget is therefore twofold: securing its infrastructure and demonstrating, through verifiable evidence, that customer assets remain protected.
Until the investigation is completed and the exchange releases its technical findings, the full chain of events behind the breach remains unresolved.
What is already clear is that the incident has turned a single security failure into a much broader test of crypto-exchange resilience, customer protection and accountability.



No Comment! Be the first one.