Someone took $387.5 million out of Bitget, and the exchange says nobody handed over a private key. Bitget CEO Gracy Chen put the loss at $387.5M in a September 25 update, up from the $351.6M the exchange confirmed hours earlier.
On-chain records show roughly $183M leaving wallets tagged to Bitget within about an hour of the first alert. Chen says the attack carries the fingerprints of North Korea, though that hasn't been confirmed and no technical evidence has been published. Bitget's own systems flagged the unauthorized transfers at 18:31 UTC on September 24.
Chen said the outflow has since stopped and no further unauthorized transfers are possible.
The thief forged the paperwork instead of stealing a key
Exchanges sort customer money into tiers. Cold wallets sit offline. Warm wallets hold a working balance.
Hot wallets are the ones wired to the internet, moving money in and out. This attack hit the top two tiers. "They did not forge user withdrawal requests, nor did they obtain our private keys of the cold wallet and any hot, warm wallet," Chen said in a livestream and a run of posts.
No user asked to withdraw. The keys were never copied. What the attacker took instead was a seat inside the system.
Chen says the intruders got into a backend piece of Bitget's wallet infrastructure and spoofed the transaction data feeding it, so the exchange's own authorization step approved payouts that looked routine. That's closer to slipping a fake withdrawal slip past a teller who checks the form and not the face.
Bitget says its security team has now identified the attack path, and the exchange is working with Mandiant and Slowmist on the forensics.
The tally moved three times in one day
The number kept growing because the assets kept moving.
| When | Estimated loss | Counted by |
|---|---|---|
| --- | --- | --- |
| Within roughly the first hour | about $183M | On-chain investigators watching wallets tagged to Bitget |
| Hours later, at Bitget's first public statement | $351.6M | Bitget |
| September 25 update | $387.5M | Gracy Chen |
More wallets tagged as Bitget's followed, pushing assets out across at least five blockchains to addresses the attacker controlled. Blockchain records put the single biggest piece at roughly 103 million XRP, worth about $157 million. Then the coins started turning into harder-to-trace assets.
On-chain researcher DCF GOD posted that a freshly created address had spent $19.67 million in USDT0, a cross-chain version of the dollar-pegged Tether, buying 7,111 ETH in six minutes at about 5% above market through UniswapX and 1inch Fusion. That premium is the interesting part.
Buying that much ether in one order would have pushed the price and told everyone watching, so the attacker paid up for speed and a quieter footprint.
Balances stay whole while a $464M fund pays out
Deposits and trading kept running through the whole thing. Withdrawals alone were frozen, as a precaution. Bitget says its User Protection Fund will cover the full loss, and that the fund holds more than $464 million.
Customer balances stay intact even though the coins have left, because the backstop pays out first and the loss lands on the fund. Chen built that cushion years ago for exactly this. It stood at $300 million in 2023.
The North Korea read is a pattern match, not a verdict
Chen has been careful about how far she takes it.
"We've identified some IP addresses that match the VPN choices by a certain DPRK group," she said, adding that "the pattern looks very much like what the North Korean team did before." She also said the on-chain signatures line up with techniques used by state-linked North Korean groups. The record gives that read some weight.
Lazarus Group, tracked under the codename TraderTraitor, was blamed for the $1.4 billion taken from Bybit in February 2025, which the FBI confirmed weeks later. Chainalysis puts North Korea's 2025 haul above $2 billion. Chen also said the same group previously drained about $80,000 from her own personal wallet outside Bitget.
It stays a lead. Chen stressed that the attacker's identity hasn't been confirmed, that no technical evidence has been made public, and that law enforcement is now involved. An IP address and a habit of moving stolen coins in a familiar order is a starting point, not a conviction.
The near-term tests are both dated. Withdrawals are frozen and Bitget says it publishes a restart plan on September 26. The $387.5M figure is also provisional, having moved twice in under a day, and a full incident report with root-cause analysis is promised once the system work is done.
Reader desk
Discuss the signal
Verified readers · 2 comments per post / 24h
No comments yet. Be the first verified reader to add context.