The most instructive detail in the Bitget breach is what the attackers did not need. There was no cracked private key, no forged customer withdrawal request and no smart-contract exploit. According to the exchange and reporting by BleepingComputer and CoinDesk, intruders compromised a backend wallet system on 24 September, spoofed the data in internal transfer requests, and let Bitget's own authorisation logic approve the movement of funds.
The scale is significant by any measure. Bitget first disclosed about $351.6 million in unauthorised transfers from hot and warm wallets, a figure later revised to roughly $387.5 million. The affected chains included Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base, across assets including ETH, XRP — the largest single-chain loss — BNB, AVAX, USDT and USDC. Withdrawals were frozen, then resumed in stages. Cold wallets and the self-custodial Bitget Wallet were untouched, and the exchange said its User Protection Fund, holding about 5,500 BTC worth more than $464 million, would cover the losses. Forensics were handed to Mandiant and SlowMist alongside law enforcement.
Attribution has been unusually direct. CEO Gracy Chen said publicly that IP behaviour patterns and on-chain analysis were "highly consistent with known patterns of North Korean hacker organisations", and that some chain operators had frozen the attacker's addresses. It is the same conclusion Western researchers have reached about the largest crypto heists of recent years — including the $1.5 billion Bybit theft — and a reminder that stolen crypto is a funding stream for missile programmes, not just a crime story.
Bitget has also said its plans to go public are unaffected, a claim worth remembering when IPO paperwork has to describe operational risk. The company says customer balances remain accurate, deposits and trading continue, and that no further unauthorised transfers are possible.
For defenders the case is a reminder that the perimeter has moved. Exchanges have spent a decade hardening key custody and signing ceremonies; the weak point here was the business-logic layer that decides a transfer is legitimate. If an attacker can make a trusted internal system believe a transfer came from an authorised source, key management never gets a chance to help.
Expect the incident to feed two ongoing arguments. Regulators will cite it as evidence that custody and approval controls need external audit, while exchanges will argue that faster cross-industry tracing of stolen funds is the only thing that actually recovers money. Bitget's phased resumption, meanwhile, raises the question customers always ask after a freeze: if the backend could authorise the theft, what else could it authorise?




