Hackers drained $352 million from Bitget without stealing a single key

iEXExchanger
Hackers drained $352 million from Bitget without stealing a single key

Crypto exchange Bitget lost nearly $352 million after attackers spoofed transaction data and tricked its authorization system, without ever touching a private key. Withdrawals are now paused.

It took less than an hour for hackers to drain roughly $352 million from crypto exchange Bitget — and they didn't need to steal a single private key to do it. On September 24, Bitget flagged unusual outflows from its hot and warm wallets and froze operations while it figured out what had gone wrong.

The method was more surgical than a typical wallet break-in. According to CEO Gracy Chen, attackers slipped into a backend system that manages the exchange's wallets, faked transaction data, and tricked the authorization process into waving the transfers through as if they were legitimate. Chen likened it to forging withdrawal slips and sliding them through a bank's own teller window — the signature is fake, but the cash that walks out the door is real.

XRP holders took the biggest hit: roughly 103 million tokens, worth about $157 million, vanished — nearly half of everything stolen. Close behind was almost 32,000 ETH (about $86 million), tens of millions of dollars in USDT and USDC, a slice of tokenized gold (XAUt), plus BNB, AVAX and TRX. The attackers wasted no time converting much of the haul into ether through a freshly created wallet, buying roughly 68,000 ETH on the open market — traders noticed the price spike in real time.

Bitget's cold storage was never touched; the breach stayed confined to hot and warm wallets. Withdrawals are paused 'as a precaution,' though deposits and trading continue as normal. The company says no customer will lose money: its User Protection Fund, which holds more than $464 million, is large enough to cover the entire loss on its own.

Chen also said some of the attackers' IP addresses matched VPN services previously tied to a North Korean hacking outfit, though she cautioned the attribution is preliminary. If it holds up, Bitget joins Bybit, which lost $1.4 billion in a strikingly similar attack in February 2025 that the FBI pinned on North Korea's Lazarus Group. The bigger lesson for the industry: cold storage isn't the only thing worth hardening. As Bitget just found out, an authorization system can be tricked into approving a transfer without anyone ever touching the actual keys.

Questions and answers

Frequently asked questions about this article

How much money was stolen from Bitget?

Bitget itself estimated the loss at about $352 million. On-chain analytics firm Lookonchain tallied a slightly higher figure of roughly $357 million across the drained wallets, including XRP, ETH, USDT, USDC and other assets.

How did hackers bypass security without stealing private keys?

According to Bitget CEO Gracy Chen, attackers compromised the backend system managing the exchange's wallets, spoofed transaction data, and tricked the authorization process into approving transfers as legitimate — bypassing the software logic rather than the cryptography itself.

Will Bitget users lose their money?

Bitget says no. Its own User Protection Fund exceeds $464 million, enough to cover the entire loss without any impact on customers. Withdrawals are temporarily paused as a precaution, while deposits and trading continue normally.

Is North Korea linked to the Bitget hack?

Bitget's CEO said some of the attackers' IP addresses matched VPN services previously used by a North Korean hacking group, but called it a preliminary lead requiring confirmation. In a similar case, the FBI officially linked North Korea to Bybit's $1.4 billion hack in February 2025.