Bitget confirmed unauthorized transfers from a portion of its hot wallets on September 24, with the exchange estimating approximately $351.6 million in affected assets. CEO Gracy Chen said the security team activated emergency response protocols within minutes of detection at 18:31 UTC.

"Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full," Chen wrote in a security notice posted the following day.

Bitget said cold wallets remain fully secure, with the breach contained to a portion of the hot wallet and warm wallet layers under the exchange's three-tier architecture. Withdrawals were temporarily suspended as a precautionary measure while the security review continues, though deposits and trading remain fully operational.

Bitget's official account echoed the same assessment.

"Based on our current assessment, approximately $351.6 million in assets were affected. Bitget's cold wallets and the overwhelming majority of platform assets remain secure and unaffected," the exchange posted on X.

Why the Protection Fund matters for user confidence

Bitget said the full loss falls within the coverage of its User Protection Fund, which currently holds more than $464 million, equivalent to 5,500 BTC at current prices. The exchange emphasized the fund's transparency:

"All fund wallet addresses are public and can be verified on-chain by anyone, at any time," Bitget wrote, adding that "losses from this hot wallet incident after assessment will be borne by the Protection Fund. We will replenish the fund."

A publicly verifiable, on-chain protection fund differs meaningfully from an exchange simply promising to make users whole from general operating capital. Because the fund's wallet addresses are published, any outside observer, researcher, or journalist can independently confirm the fund's balance and track whether Bitget actually disburses those specific reserves to cover the loss, rather than relying solely on the exchange's word. This kind of verifiable backstop has become more common industry practice following past exchange collapses where reserve claims could not be independently checked until it was too late, most notably FTX's 2022 failure, where the company's claimed customer protections turned out to be nonexistent once its books were examined in bankruptcy proceedings.

Bitget's own explanation of the fund's purpose states plainly:

"Users who have their accounts compromised or assets stolen or lost due to platform-wide events not attributable to their own actions or trading behavior may make a claim through the Bitget Protection Fund." The exchange reserves the right to assess each claim individually in relation to platform-wide incidents.

The suspected attacker and what remains unconfirmed

Reports characterizing the breach have pointed to a possible link to a North Korean-affiliated hacking group, with the attack method described as spoofing backend transaction data. Bitget itself has not confirmed this attribution publicly and explicitly declined to speculate.

"We will not speculate on the attack vector until the investigation is complete," Chen wrote in her security notice.

North Korean state-linked hacking groups, most prominently Lazarus Group and its various sub-units, have been responsible for some of the largest crypto exchange breaches in history, including the 2022 Ronin Bridge exploit that resulted in losses exceeding $600 million and the February 2025 Bybit breach that drained approximately $1.5 billion in what remains the largest single crypto theft on record. The FBI and blockchain analytics firms including Chainalysis and TRM Labs have documented a consistent pattern in these attacks: North Korean-linked actors frequently target exchange infrastructure specifically, using techniques ranging from supply-chain compromises to social engineering against employees with privileged system access, with stolen funds later laundered through mixing services and cross-chain bridges to fund the regime's weapons programs.

Bitget Wallet's separate confirmation

Bitget Wallet, the exchange's self-custodial wallet product, issued its own statement clarifying it was not affected.

"Bitget Wallet operates independently as a self-custodial wallet," the wallet's account posted. "User assets remain onchain under users' control and are separate from Bitget Exchange's custodial infrastructure."

The wallet team said a precautionary internal review found no security impact on its systems or users' self-custodial assets.

Bitget said law enforcement and on-chain security firms have been formally notified and engaged, with a full incident report including root cause analysis expected within 24 hours of the initial disclosure. The exchange committed to hourly updates across its official channels as the investigation continues.

Revolut Customers Hit by Second Breach in a Week | HODL FM NEWS
Revolut is notifying customers of a data breach at DriveWealth, its former US broker, exposing historical profile data from before December 2023.
hodl-post-image

Disclaimer: All materials on this site are for informational purposes only. None of the material should be interpreted as investment advice. Please note that, despite the nature of much of the material created and hosted on this website, HODL FM operates as a media and informational platform, not a provider of financial advisory services. The opinions of authors and other contributors are their own and should not be taken as financial advice. If you require advice, HODL FM strongly recommends contacting a qualified industry professional.