Live Prices
Markets

Bitget $352M Hack Traced to North Korea, Threatening 76% of Protection Fund

TheCryptoDesk Editorial · 2m read

Cryptocurrency exchange Bitget announced that its $351.6 million wallet breach on Sept. 24 shows hallmarks of North Korea-linked cybercriminals, presenting the platform's user backstop with its largest financial challenge to date.

Onchain Analysis Links Breach to North Korean Attackers

Bitget Chief Executive Officer Gracy Chen revealed that IP activity and transaction analysis closely match known techniques employed by state-sponsored North Korean actors. Blockchain security firms Mandiant and SlowMist have been brought in to investigate alongside relevant authorities. Onchain analyst Specter separately linked stolen XRP from Bitget to funds taken during the $24 million AFX hack in July, which was attributed to the TraderTraitor cluster associated with North Korea’s Lazarus Group.

The breach compromised ETH, XRP, BNB, AVAX, USDT, USDC, and other assets across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain, and Base. XRP recorded the largest single-network loss. While cold storage and the separately operated self-custodial product Bitget Wallet remained safe, customer withdrawals remain suspended as security checks continue following the initial hot wallet breach confirmation.

Protection Fund Faces Potential 76% Drawdown

To absorb the damages, Bitget plans to draw from its User Protection Fund, which holds 5,500 Bitcoin valued at more than $464 million. A total unrecovered loss of $351.6 million would represent approximately 76% of the fund's current dollar valuation. However, several blockchain foundations have already frozen recipient addresses tied to the exploiter, which may lower the final net loss.

Bitget holds more than $1 billion in proprietary assets beyond the fund and reiterated that user assets remain backed on a 1:1 basis. The platform's prior proof-of-reserves report published Sept. 17 documented an aggregate reserve ratio of 135% across 19 assets, though that report reflected conditions prior to the exploit. Chen stated the exchange will replenish the protection fund once the assessment finishes, but did not commit to a specific timeline for reopening withdrawals while investigators evaluate the North Korean hacking connection.

Key Takeaways

  • $351.6 Million Exploit: Hot wallets across 7 blockchains were compromised on Sept. 24, with XRP seeing the biggest loss on a single network.
  • North Korean Attribution: IP patterns and stolen XRP movements link the incident to North Korea's Lazarus Group and the AFX hack from July.
  • Fund Depletion Risk: Covering full losses directly would drain 76% of Bitget's $464 million (5,500 BTC) protection fund.
  • Operations Paused: Withdrawals stay suspended while security teams Mandiant and SlowMist conduct audits.

Why It Matters

This incident highlights the persistent risk state-sponsored hacking entities pose to centralized trading platforms. Even exchanges with substantial insurance reserves face severe operational friction when forced to halt client withdrawals during multi-chain exploits. The speed at which blockchain foundations freeze stolen assets will determine how much of Bitget's proprietary balance sheet is ultimately required to keep user deposits fully backed.

Read next