Live Prices
Markets

Bitget Suffers $351.6M Hot Wallet Breach, Covers Losses With Protection Fund

TheCryptoDesk Editorial · 2m read
Bitget Suffers $351.6M Hot Wallet Breach, Covers Losses With Protection Fund

Centralized exchange Bitget reported a $351.6 million hot wallet breach after security systems flagged unauthorized transfers at 18:31 UTC on September 24. CEO Gracy Chen confirmed that all user funds remain intact, backed fully by the exchange's $464 million User Protection Fund while withdrawals are temporarily paused.

Wallet Breach Details and Mitigation

According to Bitget CEO Gracy Chen, the attack impacted a portion of the exchange's hot and warm wallet layers, leaving cold wallets holding the majority of assets completely unaffected. Emergency protocols were triggered within minutes of detection to isolate and flag the illicit destination addresses. The root cause was identified as an intruder accessing a backend system within the wallet infrastructure, spoofing transaction data to manipulate authorization controls. Chen explicitly ruled out a private key compromise and stated that containment was verified with no further unauthorized transfers possible.

"We will not run from this, and every dollar will be accounted for," Chen posted on X, committing to publish a comprehensive incident report detailing root causes and remedial actions within 24 hours.

Suspected Lazarus Group Exploitation

On-chain investigator Specter attributed the attack to the North Korea-linked Lazarus Group, a conclusion endorsed by analyst Conor Grogan. Grogan noted, "Generally they do these on the weekends but perhaps they had a limited window for the exploit and didn't want to risk it." The attack highlights persistent exchange vulnerabilities as institutional custody models face scrutiny. Industry data indicates $1.1 billion was stolen across 212 incidents in the first half of the year, with Lazarus Group linked to over half of those total funds.

Key Takeaways

  • $351.6 million in assets were stolen across Bitget's hot and warm wallets at 18:31 UTC on September 24.
  • The exchange's $464 million User Protection Fund fully covers the shortfall, ensuring zero loss for users.
  • Attacker spoofed backend transaction data; Chen confirmed private keys were not compromised.
  • On-chain analysts point to North Korea's Lazarus Group as the likely perpetrator.

Why It Matters

Bitget's ability to absorb a $351.6 million loss using its self-funded $464 million reserve highlights the critical importance of exchange-backed protection pools during major exploits. However, the breach underscores ongoing vulnerabilities in wallet authorization backends even when cold storage private keys remain secure. As sophisticated state-sponsored actors like Lazarus Group exploit narrower operational windows, exchanges will face growing pressure from regulators and users to implement multi-layered verification protocols across all wallet tiers.

Read next