Community Trust ScoreVerified
Bitget got hit hard. The exchange lost $351.6 million in a security breach detected on September 24, and right now users can’t pull their funds out while the company scrambles through a full security review.
CEO Gracy Chen went public fast — a livestream, a direct address to the community, the works. She confirmed that a backend system tied to the wallet infrastructure was compromised. Hackers apparently manipulated transaction data to push through unauthorized fund transfers. And here’s where it gets geopolitical: Chen said preliminary findings point to North Korean hackers, with IP addresses linked to the country flagging during the investigation. But she was careful to walk that back a bit — attribution isn’t confirmed yet. It’s a suspicion, not a verdict.
Not yet, anyway.
Cold Wallets Safe, But Withdrawals Still Frozen
Chen was direct about one thing: Bitget’s cold wallets weren’t touched. The breach hit a backend system, not the cold storage layer, which is at least something. The hack was caught within minutes, and the exchange’s emergency protocols kicked in fast. Trading and deposits kept running without interruption — so the platform didn’t go dark entirely. But withdrawals? Suspended. No specific date for when they’ll come back. Users are basically stuck waiting on official updates, and Bitget hasn’t given a timeline beyond “when the security review is done.”
That’s probably frustrating for anyone trying to move money right now.
The exchange says customer balances are secure. It’s leaning hard on its User Protection Fund — a $464 million reserve built specifically for situations like this. The entire $351.6 million loss, per Bitget, will be covered by that fund. So in theory, no user takes a haircut. Whether that reassurance holds up depends on how the investigation plays out and whether the actual damage figure shifts.
Bitget also promised a detailed incident report with a root-cause analysis. No date on that either, but the company says it’s coming soon.
What Investigators Are Focused On
The piece that’s really keeping security researchers up at night: the attackers apparently bypassed authorization processes without compromising private keys. That’s not a basic attack. It suggests whoever did this understood the system’s internals well enough to manipulate transaction authorization at the backend level — without needing the actual keys to move funds. That’s a sophisticated method, and it’s the kind of thing that takes time to fully unpack.
Bitget is working with cybersecurity experts to trace exactly how the attack unfolded and to close whatever gap the hackers exploited. The exchange said it won’t speculate on the exact attack vector until its internal investigation wraps up. Fair enough — premature conclusions on something this technical tend to make things worse.
The North Korea angle, if it holds, isn’t surprising in the broader context of crypto security. State-linked hacking groups have been tied to major crypto thefts for years, and the methods keep getting more refined. But again — Chen flagged this as preliminary. IP addresses can be spoofed, and attribution in cyber incidents takes time to solidify.
Centralized exchanges carry a specific kind of risk. They hold custody of user funds, which makes them targets. The bigger the exchange, the bigger the prize. And even with a $464 million protection fund sitting in reserve, the fact that $351.6 million moved without authorization in a single incident is a brutal reminder of how exposed these systems can be.
Bitget’s response speed matters here. Catching the breach within minutes, activating emergency protocols immediately, keeping trading and deposits live — that’s not nothing. A slower response could have meant a much larger loss. But the suspension of withdrawals has created real uncertainty for users, and the lack of a hard resumption date doesn’t help.
The exchange keeps saying: stay tuned to official channels. That’s the message right now. Updates will come through Bitget’s communications as the investigation moves forward. Users have been urged to stay patient and watch for announcements.
What Bitget does next — the incident report, the root-cause breakdown, the timeline for restoring full services — will probably define how the community judges its handling of all of this more than the hack itself did.
Chen confirmed that the hack was identified within minutes and that cold wallets remained unaffected throughout the breach.
Frequently Asked Questions
How much was stolen in the Bitget hack?
Hackers transferred $351.6 million in unauthorized funds from Bitget’s wallet infrastructure on September 24.
Will Bitget users get their money back after the hack?
Bitget says its $464 million User Protection Fund will cover the full $351.6 million loss, and customer balances are reportedly secure.
Are North Korean hackers confirmed behind the Bitget breach?
CEO Gracy Chen said preliminary findings point to North Korean involvement based on IP addresses, but attribution has not been confirmed as of September 25, 2026.
Why It Matters
The security breach at Bitget highlights ongoing vulnerabilities within cryptocurrency exchanges, raising concerns about the robustness of their security protocols, especially as suspicions of North Korean involvement emerge. This incident not only impacts user trust but also amplifies regulatory scrutiny on the broader sector, as hacks like this can lead to significant market volatility and may deter new investors from entering the crypto space. As exchanges grapple with security measures, the incident serves as a reminder of the critical need for enhanced safeguards to protect user assets.





