The exchange’s CEO, Gracy Chen, said on September 25 that investigators had identified activity that strengthened the suspected North Korean connection, including VPN patterns associated with IP addresses tied to a specific group.
Chen said the evidence remains part of an ongoing investigation and that Bitget would provide a fuller account of the incident after completing its technical review.
The attack was first detected after unusual movements from wallets associated with Bitget drew attention from blockchain researchers.
According to the exchange, unauthorised transfers were made from parts of its hot and warm wallet infrastructure. Bitget said the incident did not involve the theft of private keys from its wallet system.
Instead, the attackers allegedly gained access to internal systems and used that access to initiate transfers directly.
Bitget says cold wallets were not compromised
Bitget said its cold wallets were not affected and that it had stopped further unauthorised outflows after detecting the breach.
Cold wallets are generally kept offline or isolated from internet-connected systems, while hot wallets are connected to infrastructure used for transactions and withdrawals. Warm wallets sit between the two in terms of accessibility.
The distinction is significant because an attack on internal exchange systems can allow funds to be moved without the attackers necessarily obtaining the underlying private keys.
Bitget said deposits and trading operations remained available, although withdrawals were temporarily restricted while the company carried out its security review.
Blockchain researchers spotted unusual movements
The breach became public after on-chain monitoring showed substantial transfers from wallets identified as belonging to Bitget.
Early estimates from blockchain researchers put the amount moved at about $183 million before the exchange disclosed the larger figure of approximately $351.6 million.
Arkham Intelligence analyst Emmett Gallic reported movements involving several Bitget-linked wallets across multiple blockchains. The assets identified in the transactions included Ethereum, BNB, Avalanche and USDT0.
The funds were subsequently consolidated into another address, according to the blockchain analysis.
The initial on-chain observations and Bitget’s later explanation describe different aspects of the incident: researchers tracked the movement of digital assets, while the exchange’s subsequent investigation focused on how attackers gained the ability to initiate the transfers.
Bitget says user protection fund covers the loss
Bitget said it maintains a user protection fund containing more than $464 million.
Chen said the fund was sufficient to cover the estimated $351.6 million loss associated with the incident, indicating that the company does not expect customers to bear the reported shortfall.
The statement is intended to reassure users that the breach does not automatically translate into a loss of customer balances, although the exchange’s investigation into the attack remains ongoing.
North Korea link remains under investigation
Bitget’s claim that the attack is highly likely to be connected to a North Korea-affiliated group is based on evidence identified during its investigation, including VPN and IP-related activity.
The exchange has not yet published a completed forensic report establishing the identity of the attackers.
The North Korean government has historically been accused by governments, cybersecurity companies and blockchain investigators of involvement in major cryptocurrency thefts, with stolen digital assets frequently cited as a source of funding for sanctioned activities. Attribution in individual cyberattacks, however, generally depends on technical evidence gathered during investigations.
Bitget said it would continue examining the attack route and the group responsible before releasing a detailed incident report.
One of the year’s biggest crypto exchange breaches
The scale of the reported loss makes the Bitget incident one of the largest cryptocurrency exchange security breaches reported in 2026.
It also comes after another major cryptocurrency-related attack earlier in September involving about $320 million in losses.
The Bitget incident initially put pressure on its native BGB token. Market data cited in the initial reports showed BGB falling after news of the breach emerged, while Bitcoin and Ether also recorded modest declines during the period.
The longer-term market impact will depend partly on whether Bitget’s investigation confirms that the incident was contained to the affected wallet infrastructure and whether the exchange can demonstrate that its protection fund is sufficient to meet all legitimate claims.
For now, Bitget says customer funds remain protected, its cold-wallet infrastructure was not compromised, and the reported loss falls within the resources available in its user protection fund.


















