Cryptocurrency exchange Bitget confirmed a $387.5 million breach detected on September 24, making it one of the largest crypto heists of the year. The attacker's identity remains unconfirmed, though CEO Gracy Chen has pointed to similarities with North Korean state-linked hacking groups.
How the Breach Occurred
Bitget's security systems detected unauthorized transfers from hot wallets at 18:31 UTC on September 24. Within the first hour, on-chain investigators tracked approximately $183 million in stablecoins, Ethereum, and other assets leaving exchange-controlled wallets. Total losses reached $351.6 million by the time Bitget went public hours later and climbed to $387.5 million by the following day.
According to Chen, attackers did not steal private keys or forge user withdrawal requests. Instead, they compromised a backend system within Bitget's wallet infrastructure and used it to spoof transaction data. This allowed them to trick the exchange's authorization process into approving transfers that appeared routine and legitimate.
Asset Distribution
The stolen funds were moved across at least five blockchains to addresses controlled by the attacker. The largest single haul consisted of approximately 103 million XRP, valued at roughly $157 million. Blockchain analysts observed one newly created wallet spending $19.67 million in USDT to purchase 7,111 ETH in six minutes through decentralized exchanges, paying roughly 5 percent above market price.
Response and User Protection
Chen said the unauthorized outflows have been stopped and no further transfers are possible. Bitget's User Protection Fund, which holds more than $464 million, will cover the full loss, meaning customer account balances remain intact. The exchange maintained deposits and trading throughout the incident while freezing withdrawals as a precaution. Withdrawals were scheduled to resume after the exchange announced a plan for them.
North Korea Connection
Chen identified IP addresses that match VPN choices used by what she described as a North Korean state-linked group, and noted that the on-chain signatures align with techniques tied to such actors. She emphasized that the attacker's identity has not been confirmed and that no technical evidence has been made public. Chen also disclosed that she personally lost approximately $80,000 from a wallet outside Bitget in a previous incident she attributed to the same group.
North Korea's Lazarus Group, tracked under the codename TraderTraitor, has been linked to the industry's largest breaches. In February 2025, the FBI confirmed that North Korean hackers were responsible for a $1.4 billion breach at Bybit.
Technical Investigation
Bitget pledged to release a full incident report including root-cause analysis once its technical teams complete system remediation. The exchange is working with cybersecurity firms Mandiant and SlowMist on the investigation.


