Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets.
The company discovered the breach Thursday evening after its security systems flagged multiple unauthorized transfers from a limited number of crypto wallets.
Bitget has temporarily suspended all withdrawals while investigating the incident with help from law enforcement agencies, on-chain security institutions, and cybersecurity experts at Mandiant and SlowMist.
It also said its self-custodial Bitget Wallet was not affected, as it operates on infrastructure independent of Bitget Exchange and was not impacted by the attack, and added that the User Protection Fund (which holds 5,500 BTC currently worth about $464 million) will cover all losses.
“Based on our current assessment, approximately $351.6 million in assets were affected. Bitget’s cold wallets and the overwhelming majority of platform assets remain secure and unaffected,” it said.
“The incident falls within the coverage of Bitget’s User Protection Fund, which currently holds more than $464 million. Customer account balances remain accurate, and deposits and trading continue to operate normally.”
The company has yet to share more information on how the attackers accessed its key backend wallet-service system to forge transfer information and trigger the authorization-signing process.
Bitget CEO Gracy Chen said the incident involved the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base chains and affected multiple assets, including ETH, XRP (single-chain loss is the largest), BNB, AVAX, USDT, USDC, and other tokens.
Chen added that some chains have also confirmed that the hacker wallet addresses have been frozen since the attack and linked the theft to North Korean hackers.
“Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations. We have reported to relevant institutions and are fully cooperating in conducting a global investigation,” Chen said.
“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation.”
In its latest update, Bitget said it will restore withdrawals as soon as possible, after investigators confirm it’s safe to resume normal operations.
North Korean hackers have previously been linked to many other major crypto theft incidents, including the Bybit heist, in which they stole $1.5 billion from the crypto exchange’s ETH cold wallet.

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

