
A breach at cryptocurrency exchange Bitget has put a familiar question back in front of the industry. How does a platform protect customers when an attacker does not need to steal the private keys to move money? Bitget says roughly $351.6 million was taken from its hot and warm wallets on September 24 after a critical backend system was compromised.
The exchange detected unauthorised transfers at around 18:31 UTC and suspended withdrawals as a precaution, according to blockchain intelligence firm Elliptic. The assets affected included ETH, XRP, BNB and stablecoins spread across several networks. Bitget says its offline cold wallets were not touched and that its User Protection Fund covers the loss. Those are company assurances; an independent account of how the attacker gained access has yet to be published.
The $351.6 million figure is the exchange’s reported loss. Early estimates were lower because they captured only some blockchains. TRM Labs’ tracing identified about $158 million leaving through the XRP Ledger in addition to the transfers counted on Ethereum-compatible chains. That goes a long way towards explaining the difference, though the value of stolen crypto can move with market prices.
Bitget CEO Gracy Chen says the attacker manipulated transaction data within a backend wallet system so the approval process authorised fraudulent transfers. The company says its private keys were not compromised. If its account holds up, this was a failure in the machinery around transaction approval, not a simple case of someone finding a wallet password.
That distinction matters to anyone who assumes cold storage or secure keys alone settle the security question. Exchanges need working balances online to handle withdrawals, and those hot wallets sit inside a larger web of software, staff permissions and approval checks. Compromise one trusted component and an otherwise legitimate process can be made to approve the wrong transaction.
North Korea is a leading suspect, but that is still an attribution, not a proven finding. Elliptic says the laundering routes and infrastructure overlap with earlier attacks linked to the country. TRM says some of the same connections are visible on-chain, while explicitly noting that it has not definitively attributed this theft to North Korean operators. Bitget’s CEO has also said the techniques are consistent with those of North Korea-linked groups. A fuller incident report and independent forensic evidence are still needed.
The money did not simply disappear into one address. Investigators traced proceeds across chains, with large amounts split into newly created wallets and a smaller portion moving through swaps toward Bitcoin. As of the morning of September 25, TRM said most of the stolen ETH and XRP it tracked had not moved again. That may give exchanges and investigators time to flag addresses, but tracing stolen funds is not the same as recovering them.
The suspected connection to North Korean cybercrime recalls the long history of the Lazarus Group and its reported links to earlier attacks. Here, though, it would be premature to name a specific group as the culprit. The immediate story is a very large breach and an approval system that may have been deceived. The lasting story will be whether Bitget can show precisely what failed, how customers are protected, and what it changes so the same route cannot be used again.







