Back to Newsroom
Breach

Bitget Restarts Withdrawals After $387.5M Breach Linked to North Korea

Crypto exchange Bitget has resumed Bitcoin withdrawals after suspected North Korean hackers exploited a backend flaw to steal $387.5 million from hot and warm wallets, with full service restoration staggered through early October.

Bitget Restarts Withdrawals After $387.5M Breach Linked to North Korea

Bitget Restarts Withdrawals After $387.5M Breach Linked to North Korea

Cryptocurrency exchange Bitget has begun restoring withdrawal services after a major security incident last week saw attackers drain hundreds of millions of dollars from its hot and warm wallets. The exchange now attributes the theft to a suspected North Korean state-sponsored group.

What happened

Bitget's security systems flagged a series of unauthorized transfers from a limited set of wallets, prompting the exchange to halt all withdrawals as a precaution. Initial estimates put the loss at over $350 million; a day later, updated on-chain tracing and transaction classification raised the confirmed total to $387.5 million moved to attacker-controlled addresses.

According to Bitget, the attackers compromised a critical backend system within the exchange's wallet infrastructure and used it to spoof transaction data, tricking the platform's own authorization process into releasing funds from compromised hot and warm wallets. Assets across at least seven blockchains were affected — Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain, and Base — spanning tokens including ETH, XRP, BNB, AVAX, USDT, and USDC.

Bitget says it has since identified and closed the vulnerability that was exploited, and that the incident is now contained with no further unauthorized transfers possible.

Why it matters

Bitget attributes the intrusion to a suspected North Korean threat group, based on on-chain behavior and infrastructure patterns consistent with prior campaigns. State-linked North Korean actors have been tied to a long run of large-scale crypto thefts, including the record-setting $1.5 billion theft from Bybit's Ethereum cold wallet earlier this year. Blockchain analytics firm Elliptic has estimated that North Korean-linked hackers have stolen more than $6 billion in crypto assets since 2017 — a scale that underscores how central exchange infrastructure, not just end-user wallets, has become a primary target.

Bitget maintains that user account balances were unaffected throughout the incident and that its Protection Fund covers the financial impact, with trading and deposits continuing to operate normally during the pause.

What to do

  • Exchange users: don't act on urgent "verify your account" messages referencing this incident — confirm any communication through Bitget's official channels before clicking links or entering credentials.
  • Withdrawal timing: Bitget has published a staggered resumption schedule (ETH-based networks first, then USDT networks, then remaining tokens/fiat/P2P) — check official status pages before assuming service is fully restored.
  • Exchanges and custodians generally: treat backend transaction-authorization systems as high-value targets in their own right, not just cold-storage keys — this incident hinged on spoofed transaction data tricking an internal authorization flow, not a stolen private key.
  • Security teams: review hot/warm wallet authorization logic for integrity checks that can't be bypassed by spoofed backend data, and monitor for anomalous transfer patterns even from systems considered "internal."
SHARE