Bitget suspects North Korean hackers in $351.6m theft from its hot wallets

The Bitget hack hit part of the exchange’s hot and warm wallets. Bitget says its $464m User Protection Fund covers the loss, but withdrawals stay paused while Mandiant and SlowMist investigate.


Gracy Chen smiling in a blue UNICEF cap and a navy pinstriped blazer in front of a dark event backdrop

Bitget chief executive Gracy Chen at the launch of Bitget’s partnership with UNICEF Luxembourg, 16 June 2025

Image Credits Credit: Harris de Weerd / CC BY-SA 4.0 via Wikimedia Commons (cropped)

Crypto exchange Bitget says hackers took about $351.6m from its hot and warm wallets on Thursday. It suspects North Korea. The company said on X that its systems spotted unauthorised transfers at 18:31 UTC. It has suspended withdrawals.

Chief executive Gracy Chen later spoke in a livestream on X. Investigators had traced IP addresses to VPN services once used by a North Korean hacking group, she said, as CNBC’s Matthew Tan reported. TechCrunch’s Zack Whittaker reported that the Bitget hack is the largest known crypto theft this year. The hacker has swapped most of the stolen funds on EVM chains for 67,982 Ether, worth about $183m, the blockchain analytics account Lookonchain posted on X.

“User funds are safe. The full amount of this loss falls within the coverage of Bitget’s User Protection Fund, which currently holds over $464 million,” Chen wrote in a security notice on X.

What Bitget says happened

Bitget keeps its funds in three tiers of wallets. Hot wallets stay online for everyday transfers, and cold wallets stay offline. Warm wallets sit in between. Chen said the breach reached only part of the hot and warm layers. The cold wallets are secure, she said.

The attacker broke into a critical backend system in the wallet infrastructure, according to Chen. They used it to fake transfer data and set off Bitget’s own signing process to move the funds out. There were 19 transfers, CNBC reported.

“Private key compromise has been ruled out,” Chen said, according to CNBC.

The stolen assets include Ether, XRP, BNB, AVAX, USDT and USDC, according to CNBC.

Bitget said on-chain estimates of about $183m had missed activity on some of the chains, CNBC reported.

Withdrawals paused, investigators in

Deposits and trading continue as normal, and Bitget says customer balances are accurate. It has told law enforcement and blockchain security firms. It promised a full incident report, with the root cause, within 24 hours.

On Friday, the company said that Mandiant and SlowMist were carrying out an independent investigation. Bitget Wallet, its self-custodial app, runs on separate infrastructure, and the incident did not touch it, the company added.

Chen gave no firm date for withdrawals to restart. They could return within hours or days, she said in a broadcast on X. But it “shouldn’t take weeks”, she added, according to CNBC.

Bybit chief executive Ben Zhou said his team was ready to help, CNBC reported. Bybit lost $1.5bn in a hack in February 2025.

Earlier attacks

North Korea is behind about three-quarters of all crypto theft in 2026 so far, TechCrunch reported, citing blockchain intelligence firm TRM Labs. Its hackers have also targeted open-source developers. Some are building their own AI tools to get around AI guardrails.

Separately, hackers took $3m from Polymarket users in June in a third-party vendor breach.

Bitget, founded in 2018, says on its website that it has 120 million registered users.

Get the TNW newsletter

Get the most important tech news in your inbox each week.

Published
Back to top