On-chain data is more honest than official announcements. Arkham saw it first: a newly created address consolidated 180–190 million from a Bitget-labeled wallet. The earliest move: 19.67 million USDT on Arbitrum was swapped for 7,111 ETH in six minutes, at a trade price 5% higher than the market rate. What kind of person would urgently buy with a 5% premium? Someone who’s rushing to convert USDT into ETH—which no one can freeze.
And then it’s the standard money-laundering pipeline. Stablecoins, gold tokens, AVAX, BNB—everything is stuffed into the same address, then split across different chains, with Stargate and cBridge bridging back and forth. Tether and Circle can freeze USDT and USDC, but no one can freeze ETH. This guy knows the ropes.
Bitget CEO Gracy Chen said the user protection fund is 464 million, fully covers losses, and that cold wallets are secure. The numbers look good. But look at another number: after the news came out, Bitget’s BGB token dropped 5%, and then the entire crypto market rose by nearly 10% over the past week. The market is saying one thing: this is a Bitget problem, not an industry problem.
Doesn’t this sound familiar?
In February 2025, Bybit was hacked for 1.4 billion. What did Bitget do then? It deposited 40,000 ETH into Bybit—its own money, not users’. CZ said at the time, “If it’s needed, we’ll help,” and then it was spread that Binance also stored ETH. CZ came out to deny it, saying it was users’ actions, not Binance’s.
Now it’s Bitget’s turn. Who’s storing ETH for it?
Look back at history. When Bybit was hacked, it was attributed to North Korea’s Lazarus. This time with Bitget, Specter traced the funds on-chain and found the stolen XRP could be linked to the $24 million stolen from AFX in July—same organization, TraderTraitor, a subordinate unit of Lazarus. Gracy Chen herself said in a livestream that the traced IP matched a North Korean VPN.
It’s North Korea again. Same playbook again. In 2025, Bybit—$1.4 billion. In 2026, Bitget—$350 million. Who will it be next, when, and how much will be stolen? No one knows. But there’s one thing you do know: the attackers haven’t changed; the methods are upgrading, while the defenders are still getting hit using the same stance.
Now let’s talk about Binance.
CZ said something back in August that got a lot of people cursing at the time. He said, based on data, putting coins in a centralized exchange is safer than self-custody. He cited River’s industry report: self-custody lost 1.57 million BTC, exchanges lost 1.51 million BTC—self-custody lost 60,000 more. CZ’s view is that when exchanges get hacked, it makes headlines; when self-custody loses coins, nobody knows. So the real losses from self-custody are underestimated.
Put this in context today—it’s especially interesting.
Bitget was hacked for 350 million, and it made every headline. A retail user lost their mnemonic phrase, losing 0.5 BTC—nobody reported it. What you see is “the exchange is having problems again.” What you don’t see is “next door, Old Wang lost his private key again.”
The meaning of “CZ’s isn’t that exchanges are absolutely safe.” His point is that safety isn’t a binary choice—it’s a game of probability. If you choose to trust a centralized institution, you’re betting on its risk controls, its reserves, and its protection fund. If you choose self-custody, you’re betting on your own memory, your hardware, and your operating habits. Two different bets, different odds, but neither one is a sure win.
Binance hasn’t never had issues either. But look at its size, its SAFU fund, and its compliance architecture. Its investment in security isn’t on the same scale as a second-tier exchange. This isn’t saying Binance won’t have incidents. It’s saying when someone gets stolen from in the industry, where does the money tend to run to.
Bitget got hacked, withdrawals are paused. Users’ money can’t move for now. And then what? When withdrawals resume, some people will withdraw and move to somewhere else. Where to? Binance is the default option. Not because it’s the best, but because it’s the biggest. The biggest one has the highest cost to steal, the hardest to pull off, and the strongest ability to cover the fallout if something happens.
This isn’t an ad. It’s physics.
Bitget can take it. The 464 million protection fund is real, and Gracy Chen’s public response is also presentable. But trust—like liquidity—flows to where there’s the least resistance. Bitget’s resistance is now higher, while Binance’s relative resistance is lower.
If you ask me what I’m doing now—I’m doing nothing. I don’t have any Bitget positions, and I didn’t open any trades because of this. I’m just watching: watching when withdrawals get restored, watching where the capital flows, and watching who gets hit next.
North Korea doesn’t pick and choose exchanges. It goes after the one with the weakest defenses. The only thing you can do is not stand in that position.
— Pure water channel #bitget遭黑客攻击损失3.52亿美元