Breaking: North Korean Hackers Strike Again, Bitget Hot Wallet Loses Over $350 Million
- Key Takeaways: Bitget's hot wallet was hacked, resulting in losses of approximately $351.6 million. Officials stated that cold wallets and most assets were unaffected, and the User Protection Fund can fully cover the losses. The incident exposed security vulnerabilities in the hot wallet segment.
- Key Details:
- The attack occurred at 2:31 AM, with hackers infiltrating the wallet infrastructure backend system to forge transaction data. Private key leakage has been ruled out.
- Stolen assets include ETH, USDT, USDC, XAUT, BNB, AVAX, and others, spanning multiple public chains including Arbitrum and Avalanche.
- Bitget employs a three-tier wallet architecture consisting of hot, warm, and cold wallets. Only some hot wallets and warm wallets were affected in this incident; cold wallets remain secure.
- The platform has suspended withdrawals, law enforcement agencies have launched an investigation, and the User Protection Fund, valued at over $464 million, can cover the losses.
- CEO Gracy Chen stated that some IPs matched those of North Korean hacker group VPNs, though this has not been definitively confirmed. Insider involvement has been preliminarily ruled out.
Original | Odaily (@OdailyChina)
Author | Wenser (@wenser 2010)

It's Mid-Autumn Festival again, but what arrived earlier than the holiday was yet another large-scale CEX hack in the industry.
At 2:31 AM today, some of Bitget's hot wallets saw large-scale abnormal transfers. Initial on-chain monitoring put the stolen funds at over $100 million, and the figure was soon confirmed by Bitget officials to have expanded to $351.6 million.
The official statement said that cold wallets and the vast majority of the platform's assets were unaffected; Bitget's User Protection Fund currently stands at over $464 million, sufficient to fully cover the stolen assets. Currently, out of consideration for fund security, Bitget has temporarily disabled withdrawals, which will be restored in an orderly manner once security verification is complete; law enforcement agencies and on-chain security firms have launched investigations; the platform will continue to provide hourly updates and release a full incident report within 24 hours, including root cause analysis and remediation measures.
To boost user confidence, Bitget CEO Gracy Chen also hosted a livestream to share the latest developments and current status in real time.

From Binance to Bybit, nearly every leading exchange has faced similar hack attacks head-on. Coinciding with Bitget's 8th anniversary, this attack may serve as an important trial by fire for this veteran exchange — testing not only its security defenses, but also the depth of trust, resilience in response, and the caliber of its brand.
Hot Wallet Suddenly Ransacked by Hackers, Losses Exceeding $350 Million
At 3:57 AM, crypto trader DCF GOD posted that Bitget's hot wallet appeared to have been attacked, with losses of $20 million. Specifically, a new wallet address 0xe410 used 19.67 million USDT from Bitget's hot wallet to buy 7,111 ETH on Arbitrum via UniswapX + 1inch Fusion within 6 minutes, at a premium of up to 5% over the spot price. At the time, the WETH/USDC liquidity pool was only $2,870 — if someone simply wanted to buy ETH, this made no sense at all.
External Perspective: Hacker Test Transfers, Bitget Quickly Responds by Suspending Withdrawals and Consolidating Assets
At 4:08 AM, The Block's head of research Steven followed up with a post: "Over the past hour, approximately $174 million in funds have been transferred from hot and cold wallets to address 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee across multiple public chains." Notably, unlike previous security incidents where large transfers were executed quickly, on-chain data shows the hacker even conducted small-amount test transfers.
At around 4:12 AM, Steven monitored that Bitget had apparently suspended withdrawals, at which point assets in its related hot and cold wallets still amounted to as much as $500 million, preventing further expansion of losses. He also offered his own speculation: "I lean toward believing this is indeed a hack, but not a large-scale attack — rather, a few less secure wallets exposed vulnerabilities."

At 4:50 AM, on-chain data showed that some of Bitget's hot wallet assets were consolidated to cold wallet address 0xffa8DB7B38579e6A2D14f9B347a9acE4d044cD54, but that cold wallet subsequently transferred the funds to the hacker's address.
Industry experts believe this may not be a theft of the exchange's private keys, but rather the work of a major Bitget client, which would explain (1) why the hacker did not steal all the funds in Bitget's wallets; and (2) why Bitget's wallet address would consolidate funds to a wallet address that had previously transferred funds to the attacker.


At 5:10 AM, on-chain data showed that $8 million in USDC on the Avalanche chain was transferred to the hacker's address, and the exploit was still ongoing.

At 5:30 AM, Bitget CEO Gracy Chen officially released a statement, detailing the scale of the stolen funds, the timing, emergency response plans, and follow-up procedures, as the related security response system began operating rapidly and methodically; Bitget's Chinese-language lead Xie Jiayin subsequently also posted a quick briefing on the specifics of the hack. Notably, in the subsequent CEO livestream, Gracy Chen also emphasized that Bitget employs a three-tier hot, warm, and cold wallet architecture, and this hack only involved some hot and warm wallets, with cold wallets and the vast majority of platform assets unaffected.
Key Information on the Hack: Hacker Wallet Addresses, Bitget Official Wallet Addresses, Details of Stolen Assets
At around 5 AM, on-chain monitoring platform Bubblemaps posted that the hacker first consolidated funds to 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee; then after asset swaps, further distributed them to the following addresses:
- 0x469Ac1406dE92f82C0563477240a3627057425DC;
- 0xe410a2E5710Ee787bcaa63f52A3943ff71F0d946;
- 0xD2C2f029eFF5caCc686F24377CfdDcfc82d9F899;
- 0x7c96279Ec1e888Aa56b9B836e0dB26ca48573E1C;
- 0x94A43df7687A8494948Be937400e9d5D33135DA0;
- 0xA6dD3F218B65E32Ccc37BE30f74884133c655545.

Bitget's compromised hot wallet addresses include:
- 0x1AB4973a48dc892Cd9971ECE8e01DcC7688f8F23;
- 0xffa8DB7B38579e6A2D14f9B347a9acE4d044cD54;
- 0x97b9D2102A9a65A26E1EE82D59e42d1B73B68689;
- 0x5bdf85216ec1e38D6458C870992A69e38e03F7Ef;
- 0x1AB4973a48dc892Cd9971ECE8e01DcC7688f8F23.
At 5:42 AM, Bitget Wallet officially issued a notice, advising users to temporarily revoke wallet-related contract approvals and await further official review and confirmation.
As of 5:33 AM, when Bitget officials issued their notice, according to Bubblemaps monitoring, the total amount of funds stolen in Bitget's hack reached $191 million, with the main stolen assets including ETH, USDT, USDC, USDT0, XAUT, BNB, and AVAX, with specific figures as follows:

Cause of the Theft: North Korean Hackers? Departing Employees? Or Something Else?
As of the time of writing, the specific details of Bitget's massive asset theft have not yet been released. Some in the market speculate it may be the work of the Lazarus Group, the North Korean hacker organization behind the $1.5 billion Bybit theft; crypto KOL and Hertzflow founder Crypto Skanda called on Bitget officials: "I suggest thoroughly investigating departing technical department personnel."
Based on available information, the security vulnerability occurred in the hot wallet segment, and many also speculate it may be the work of an internal employee, which is also consistent with the pattern of a further approximately $8 million being transferred from a hot wallet to the hacker's main address even after Bitget officially suspended withdrawals.

Latest news: Bitget CEO responded in a public post: "What can be confirmed so far: Attack phase: Bitget's security team has made initial progress in tracing the source of the attack. The hacker compromised a critical backend system within its wallet infrastructure, exploited it to forge transaction data, and triggered our authorization process to transfer out funds. Private key leakage has now been ruled out — meaning the more severe related scenarios do not apply. Fund losses have been contained, and no further unauthorized transfers will occur. The specific method of system intrusion is still under active investigation, and we will release a full technical report once the relevant information is confirmed.
Regarding resumption of withdrawals: Multiple technical teams are concurrently carrying out system repairs and security hardening, while also preparing for the resumption of withdrawals. Once the specific timeline is determined, Bitget officials will announce it as soon as possible."
In addition, during the platform security incident livestream Q&A, Gracy Chen also stated that preliminary investigations found that some related IP addresses match VPN services used by a certain North Korean hacker group, and the attack pattern bears similarities to the group's previous operations, so their involvement in this attack involving approximately $351.6 million cannot be ruled out, though the attacker's identity has not yet been definitively confirmed. She also stated that Bitget currently does not believe this incident was an inside job. The attacker moved funds by compromising platform systems, did not forge user withdrawal requests, and did not obtain cold wallet or hot wallet private keys. The team is still investigating the specific affected systems and the attacker's method of intrusion.
We hope Bitget can weather this trial. At this critical moment of a bull market restart, the crypto industry simply cannot afford another large-scale security storm.


