Bitget, one of the world’s largest cryptocurrency exchanges, was hit by a hot wallet security breach on September 24 that resulted in approximately $351.6 million in unauthorized transfers — and CEO Gracy Chen says preliminary evidence points to North Korea’s Lazarus Group as the likely culprit.
The exchange has temporarily suspended withdrawals while it investigates, but says user funds remain fully protected through its dedicated User Protection Fund, which holds more than $464 million in reserves.
How the Incident Unfolded
According to Bitget’s official statement, the exchange’s security systems detected unauthorized transfers involving a limited number of hot wallets at 18:31 UTC on September 24, 2026. The company said its security team immediately activated emergency response procedures and launched a full investigation. Based on Bitget’s assessment, approximately $351.6 million in assets were affected, involving 19 separate transfers drawn from portions of its hot and warm wallet infrastructure.
Bitget emphasized that the exchange’s cold wallets — offline storage systems holding the overwhelming majority of platform assets — remain secure and were not impacted. Affected assets spanned multiple blockchains, including Ethereum, XRP Ledger, Avalanche, BNB Smart Chain, and Arbitrum, with XRP representing the single largest stolen asset at nearly $157.5 million.
How the Attackers Reportedly Pulled It Off
According to Bitget’s own technical assessment, the attackers did not steal user private keys or compromise customer wallets directly. Instead, the exchange’s security team said hackers breached a backend wallet system, forged transfer details, and then triggered Bitget’s normal transaction-signing process — making the outgoing transfers appear legitimately authorized rather than fraudulent.
Chen described the incident during a livestream as a direct breach of Bitget’s internal systems, clarifying that attackers moved funds directly rather than forging withdrawal requests tied to individual customer accounts. The precise method used to initially access the backend system remains under investigation.
Why North Korea Is Suspected
Speaking during a livestream on X, CEO Gracy Chen said investigators had identified IP addresses linked to VPN services previously associated with a North Korean hacking group, and that the overall pattern of the attack closely resembled prior operations attributed to North Korean state-linked actors. Chen was careful to note that the attacker’s identity cannot yet be confirmed with complete certainty, but said the available evidence points toward Lazarus Group involvement.
Independent blockchain investigators have offered mixed views on the specific attribution. One analyst using the handle @SpecterAnalyst on X claimed to have linked the Bitget hack to an earlier $24 million breach of AFX in July, which was specifically attributed to TraderTraitor, a North Korea-linked hacking unit, noting that stolen XRP from Bitget was bridged and could be directly traced to funds from that earlier theft.
Other on-chain analysts have pushed back on automatically labeling every major exchange hack as “Lazarus,” with one commentator noting that the name has become something of a catch-all term for various North Korean cyber operations rather than a single identifiable group. As of publication, Bitget has not released specific on-chain evidence directly tying the stolen funds to previously identified Lazarus-controlled wallets.
If confirmed, the suspected North Korean involvement would fit a well-documented pattern: Lazarus and affiliated groups have been blamed for several of the largest crypto exchange thefts in recent memory, including the record $1.5 billion Bybit hack in February 2025, the $308 million DMM Bitcoin collapse in 2024, and the $234.9 million WazirX breach the same year.
Industry Support Following the Breach
In a notable show of industry solidarity, Bybit CEO Ben Zhou said his team was standing by to assist Bitget with its investigation — a reciprocal gesture, given that Bitget had previously helped support Bybit with 40,000 ETH following Bybit’s own record-setting hack in 2025. Zhou added that Bybit is updating its LazarusBounty platform specifically to help trace the funds stolen from Bitget.
What’s Working and What Isn’t for Users
Bitget moved quickly to clarify the practical impact for customers. Account balances remain accurate, and both deposits and trading continue operating normally. Withdrawals have been temporarily suspended as a precaution while the security review continues. The exchange said it has flagged the relevant transfer addresses and formally engaged law enforcement agencies and blockchain security partners, adding that several blockchain foundations have already frozen certain attacker-controlled wallets. Bitget committed to hourly public updates and pledged to publish a full incident report with root-cause analysis within 24 hours of the breach.
How the Protection Fund Will Cover the Loss
Bitget confirmed that losses will be absorbed by its Protection Fund rather than passed on to users:
“The Bitget Protection Fund exists for moments like this. It holds 5,500 BTC, approximately $464M at current prices.”
The company emphasized the fund’s transparency, noting all fund wallet addresses are public and verifiable on-chain at any time, and confirmed it plans to replenish the fund following the payout, with further details on that process to be announced separately.
Who Bitget Is
Founded in 2018, Bitget ranks among the world’s top five cryptocurrency derivatives exchanges by scale, serving an estimated 45 million to 120 million registered users across more than 150 countries and generating over $20 billion in daily trading volume across more than 800 spot trading pairs.
Part of a Broader Pattern
Bitget’s breach, now considered the largest single crypto exchange hack reported so far in 2026, adds to a difficult year for exchange and protocol security that has already included major incidents at Balancer, Cronos-based Tectonic, Ostium, and hardware wallet makers SafePal and Trezor.
What Happens Next
With law enforcement and blockchain security firms now formally engaged, and several blockchain foundations already freezing suspect wallets, the coming days should bring further clarity on both attribution and the timeline for restoring withdrawals. Bitget has committed to ongoing transparency as its investigation continues, while trading and deposit functionality remain unaffected in the meantime.
