Bitget has disclosed a $351.6 million breach affecting portions of its hot and warm wallet layers, with the exchange confirming that user funds will remain protected through its User Protection Fund.
The exchange's security systems flagged the unauthorized transfers at 18:31 UTC on September 24. According to CEO Gracy Chen, emergency protocols activated within minutes of detection, identifying and reporting the addresses involved in the abnormal activity.
Wallet System and Fund Coverage
Bitget operates a three-tier wallet structure. Cold wallets, which hold the majority of the exchange's assets, were not affected by the breach. The exchange's User Protection Fund currently holds more than $464 million, exceeding the $351.6 million loss.
"We will not run from this, and every dollar will be accounted for," Chen stated in an update on X. The exchange has paused withdrawals as it reviews the incident and plans to release a full incident report within 24 hours of the initial notice.
Attack Method
Bitget attributed the breach to an attacker who accessed a backend system within its wallet infrastructure, spoofed transaction data, and manipulated the exchange's authorization process to release funds. Chen ruled out a private key compromise and confirmed that containment measures are in place, preventing further unauthorized transfers.
Attribution Questions
On-chain investigator Specter has suggested the North Korea-linked Lazarus Group may be responsible for the attack, a view supported by analyst Conor Grogan. Grogan noted that while the group typically conducts operations on weekends, it may have acted on a limited timeframe to avoid missing the exploit window.
The incident occurs amid a broader pattern of cryptocurrency exchange breaches, with $1.1 billion stolen across 212 incidents in the first half of the year, more than half traced to the Lazarus Group.


