Bitget disclosed that unauthorized transfers hit its hot and warm wallet layers, prompting an immediate halt to all withdrawals. The loss totals roughly $351.6 million, making it one of the largest crypto-exchange breaches of the year.

Initial clues

During a live Q&A on X, chief executive Gracy Chen highlighted that investigators identified IP addresses matching VPN services commonly employed by a North Korean hacking collective. She noted the similarity of the tactics to earlier attacks attributed to the same state-linked actors, including the $1.5 billion Bybit compromise that the FBI linked to North Korea.

How the attackers operated

According to Chen, the perpetrators bypassed the usual method of forging user withdrawal requests. Instead, they accessed Bitget’s infrastructure and transferred assets straight from the compromised wallets. The breach did not involve the theft of private keys for either cold storage or the exchange’s hot and warm wallets, suggesting a different point of entry.

Ongoing investigation

The exchange has not yet determined which specific systems were infiltrated or the exact method used to gain access. Chen emphasized that the incident does not appear to be the result of insider involvement. Bitget is working with blockchain foundations and other partners to trace the stolen funds and assess the full scope of the compromise.

Recovery efforts

While the company confirmed that a portion of the missing assets has been recovered, it did not disclose the precise amount. Ongoing collaboration with industry groups aims to retrieve the remaining funds and strengthen security measures.

Broader context

North Korean cyber units have been linked to roughly $2.02 billion in cryptocurrency thefts throughout 2025, according to security analysts. Their operations often leverage VPNs to mask origins, complicating attribution and response.

Why it matters

The incident underscores the persistent threat posed by state-backed hacking groups to the broader crypto ecosystem. It also highlights the challenges exchanges face in protecting hot-wallet infrastructure, even when cold-storage keys remain secure. As regulators and industry participants push for stronger safeguards, the Bitget breach may accelerate discussions around mandatory security standards and cross-border cooperation in crypto-asset recovery.