Bitget says its preliminary investigation into a 351.6 million USD wallet breach has found no leak of private keys — instead pointing to a compromise of a core backend wallet service that fed false transfer data into the exchange’s approval-signature process.
The exchange detected unauthorized transfers at 18:31 UTC on Sept. 24 and activated emergency procedures within minutes. An estimated 351.6 million USD in assets were affected, with the incident reaching portions of Bitget’s hot and warm wallet layers. Cold wallets remained secure under the company’s three-tier classification. Withdrawals remain suspended, while deposits and trading continue.
How the attack apparently worked
During a live Q&A after the breach, CEO Gracy Chen said investigators had ruled out a leak of the private keys used across Bitget’s cold, warm and hot wallets. Instead, attackers entered Bitget’s systems and transferred funds directly — without using customer withdrawal requests.
A report on the session said Bitget’s security team identified part of the attack route: a compromise of a core backend wallet service, where false transfer data reached the exchange’s approval-signature process. In effect, the signing layer appears to have approved transactions it believed were legitimate because the backend supplying transaction details had been compromised upstream.
Bitget has not yet published the technical evidence behind that finding, and the company’s first public notice was deliberately cautious — “We will not speculate on the attack vector until the investigation is complete.” The backend-system finding therefore remains preliminary until the promised root-cause report is released.
The architecture echoes earlier supply-side attacks. After the 1.4 billion USD Bybit theft in 2025, forensic investigators traced the attack to compromised Safe infrastructure — the signing interface sitting between the exchange and the blockchain — while Bybit’s own security systems remained intact. Bitget’s case appears to involve a different component, but the same principle: the attacker compromised the layer that tells legitimate signing infrastructure what to sign.
On-chain tracking puts XRP at the top
Lookonchain estimates the stolen portfolio at roughly 356.8 million USD using token prices at publication time, slightly above Bitget’s internal estimate — the figures come from separate accounting methods and should not be treated as identical measurements.
The breakdown lists 102.93 million XRP worth 157.48 million USD as the largest component, followed by 31,890 ETH valued near 85.75 million USD. The rest includes 34.75 million USDT, 21.05 million USDC, 19.67 million USD₮0, 3,000 XAUt, 12,719 BNB, 821,012 AVAX and 20.59 million TRX. Earlier tracking produced lower totals — Wu Blockchain recorded visible Bitget-linked flows of roughly 178 million to 190 million USD before the exchange disclosed its fuller estimate, illustrating how on-chain accounting lags reality while transfers are still unfolding.
North Korea suspicion, carefully hedged
Chen raised a possible North Korean connection during the Q&A, saying investigators had identified IP addresses whose VPN usage matched those associated with a DPRK hacking group. “We’ve identified some IP addresses that match the VPN choices by a certain DPRK group,” she said, later describing the pattern as similar to previous North Korean operations.
She stopped well short of attribution. No government agency has publicly tied the Bitget breach to North Korea, and Bitget said it does not currently believe the incident involved an insider. The company’s suspicion is preliminary — a pattern match, not a confirmation.
North Korea has been formally linked to major exchange thefts before. Bybit filed a U.S. federal lawsuit against North Korea, its Reconnaissance General Bureau and the Lazarus Group over the February 2025 theft, an attack the FBI attributed to North Korean actors. North Korea-linked operations also drained 577 million USD from Drift Protocol and KelpDAO in April 2026, though those cases involved different attack paths.
Balance sheet versus the loss
Bitget says customer account balances remain accurate and that its User Protection Fund, valued at more than 464 million USD, can cover the estimated loss. Law enforcement and on-chain security firms have been notified, and addresses tied to the abnormal transfers have been flagged. Chen said some stolen funds had been recovered without disclosing an amount, and that Bitget is working with blockchain foundations and other partners on recovery.
No independently verified total for frozen or recovered assets has been disclosed, and Bitget has not published a transaction-level reconciliation explaining the gap between its estimate and Lookonchain’s market-value calculation.
Withdrawals will return only after the security review is complete, with no fixed restart time announced by early Sept. 25. Engineering teams were still repairing systems, strengthening controls and preparing withdrawal services for reopening.
The takeaway for custodial security
The most sobering detail is what did not fail. Private keys stayed secure. Cold wallets stayed untouched. The attacker never needed either — reaching through the backend that orchestrates transfers and getting the legitimate signing process to do the work. For exchanges, that shifts the defensive perimeter yet again: key management is necessary but nowhere near sufficient when the systems surrounding the keys can be made to lie.
A full incident report is expected once the investigation concludes. Market snapshot at 12:00 UTC on Sept. 25: BTC 84,606 USD, ETH 2,716.64 USD, SOL 120.81 USD.
a backend feeding fake transfer data into the signing process is way scarier than a leaked key. the signer approved garbage because it trusted its own source
exactly. cold wallets ‘secure’ but the approval-signature flow was the weak link the whole time. XRP being the single biggest loss is rough for those bag holders
a second signer validating against on-chain state would have caught the fake transfers instantly. trusting your own feed is the design flaw
351.6 million gone and deposits plus trading kept running while withdrawals froze. reads like they’re still not sure how wide the hole is
detected at 18:31 UTC and ’emergency procedures within minutes’, yet 351.6M still walked out the door. speed doesn’t help much when the signer itself is compromised
backend compromise instead of a key leak, same playbook as Bybit with Safe. the signing layer was fine, the thing feeding it data was lying. brutal
exactly the Bybit comparison. at what point do exchanges stop blindly trusting their own internal services that feed the signer
withdrawals still suspended while trading continues. so i can watch my bag move but not touch it. cool cool cool
standard procedure after a breach tbh, reopen withdrawals too early and you invite a second run on the hot wallets
the fun part is trading still works so the fees keep flowing while you cant touch your xrp. priorities on full display after a 351.6m backend breach
351.6M gone and XRP being the single biggest loss is strange. drainers usually grab stables first for clean exits
XRP being the biggest loss fits whatever sat in the warm layer that night. drainers with a shopping list would take stables