
The CEO of crypto exchange Bitget has confirmed that a cyberattack with all the hallmarks of a North Korean operation resulted in approximately $387.5 million worth of digital assets being stolen from the exchange’s wallets.
Bitget initially estimated the loss at $351.6 million, but later revised the figure to $387.5 million after identifying additional affected assets on Zcash and TRON that were not included in the initial estimate.
Blockchain intelligence company Arkham published its preliminary observations of the attack, estimating at the time that roughly $350 million was stolen and that $228 million left Bitget’s wallets in 18 minutes, between 18:58 and 19:16 UTC.
Arkham said $153 million worth of XRP was taken from a wallet it identified as a Bitget cold wallet, while the stolen assets also included $66.2 million of ETH, $34.8 million of USDT, $12.9 million of USDC, and $12.8 million of Tether Gold on Ethereum. Other affected networks included Arbitrum, Optimism, BNB Smart Chain, Avalanche, and Base.
However, Chen said Bitget's cold wallets and customer balances remained unaffected, while its User Protection Fund held more than $464 million worth of assets.
“To be transparent about our financial position: beyond the $464M+ Protection Fund – all held in publicly verifiable wallets – Bitget holds over $1 billion in its own assets,” Chen said.
“User funds are covered on a 1:1 basis.”
Chen also explained that Bitget Wallet, the company’s self-custody product, operates on infrastructure separate from its exchange, and Bitget users can still make deposits and trade their tokens, despite withdrawals being temporarily suspended while additional security checks are completed.
Bitget said it also engaged incident response giant Mandiant and blockchain security outfit SlowMist to help with the investigation into the attack.
Chiefs at fellow exchanges rallied around Bitget in support.
“MEXC stands ready to support Bitget in any way we can,” said CEO Vugar Usi. “In moments like this, the industry is stronger when we stand together.”
Binance co-CEO Richard Teng also pledged Binance's support for Bitget, saying it had shared intelligence and helped trace the stolen funds.
Ben Zhou, CEO of Bybit, said his company was on standby to “help in any way we can,” noting that Bitget helped it out following the $1.5 billion Bybit theft the FBI attributed to North Korea in February 2025.
How and who
Root cause analyses typically take some time, although according to Chen, Bitget's security team has already identified the wallet service's backend system as the source of the unauthorized transfers.
“Hackers breached a key backend system of the wallet service and exploited it to forge transfer information and invoke the authorization signing process, thereby transferring funds out,” she said.
“The possibility of private key leakage can be ruled out – this means a more severe risk scenario has been eliminated. Damage control has been confirmed as complete, and there is no risk of further fund outflows from the platform.
“The specific intrusion methods used by the hackers are still under technical investigation, and a full report will be released upon completion of the investigation.”
Chen did not go into too much detail about the alleged links to North Korean state-sponsored attackers having a hand in the attack, but said “IP behavioral patterns and on-chain signatures” suggest it was Kim’s cronies at work.
It would come as little surprise if North Korea was indeed the culprit behind the attack. The regime has a knack for hacking crypto exchanges.
The aforementioned hit on Bybit was perhaps North Korea’s biggest crypto haul, although similar lucrative ventures attributed to North Korean attackers have come at the expense of DMM Bitcoin and WazirX, among others.
Bitget was founded in 2018, registered in the Seychelles in 2022, and operates through regional hubs across the world.
Some netizens have speculated that the timing was especially inconvenient, with the transfers detected at 18:31 UTC – 02:31 on September 25 in Singapore and China, the first day of China’s three-day Mid-Autumn Festival holiday. The festival is also widely celebrated in Singapore, although it is not a public holiday there.
asked Bitget whether this played a role in the attack and its remediation but it did not respond.
As of Friday, Bitget is offering bounties to those who help freeze or recover the stolen funds. It said eligible participants could receive 5 percent of the funds their efforts successfully freeze or recover.®