Bitget disclosed that a breach of its hot wallet on September 24 resulted in the loss of $351.6 million worth of various digital assets. The exchange said the movement of funds and associated IP addresses bear the hallmarks of North Korean hacking groups, a claim supported by on-chain analyst Specter who linked the stolen XRP to the $24 million AFX hack from July, which has been attributed to the TraderTraitor cluster tied to the Lazarus Group. Bitget has notified relevant authorities and enlisted the security firms Mandiant and SlowMist to investigate, while noting that the attribution is still under review and has not yet been independently confirmed by its external partners.
The compromised assets spanned multiple networks, including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain and Base, with tokens such as ETH, XRP, BNB, AVAX, USDT and USDC affected. According to CEO Gracy Chen, XRP represented the largest single-network loss. Bitget added that several blockchain foundations have already confirmed freezes of addresses believed to be controlled by the attacker, which could reduce the final impact if those funds are recovered.
The incident puts pressure on Bitget’s User Protection Fund, which holds approximately 5,500 Bitcoin valued at more than $464 million. A full loss of $351.6 million would equal about 76% of that fund’s current value, though the exact draw will depend on any successful recoveries and fluctuations in Bitcoin’s price. Chen said the exchange would replenish the fund after covering the incident and noted that it also controls over $1 billion in proprietary assets, with customer balances maintained on a one-to-one basis. The exchange’s latest proof-of-reserves report, published on September 17, showed an aggregate reserve ratio of 135% across nineteen assets, but that snapshot predates the breach and does not reflect the post-attack position.
Withdrawals from the platform remain suspended as Bitget conducts additional security checks. Chen stated that the exchange will announce a reopening window only when it can do so with confidence, rather than committing to a timetable before the review concludes. Investigators are pursuing two parallel goals: attempting to recover the stolen assets before they become untraceable and determining how much of Bitget’s own balance sheet will ultimately be required to make users whole.
Why it matters
The breach highlights the continuing threat posed by state-linked cyber groups to centralized crypto services and tests the effectiveness of exchange-backed insurance mechanisms. If a large portion of the protection fund is depleted, it could affect user confidence and prompt other platforms to reassess the size and liquidity of their own safeguards. The outcome of the investigation may also influence how regulators view the adequacy of self-insured funds in the industry.




