Bitget Hack Exposes Crypto's Authorization Problem
Bitget's $387.5 million breach shows why protected keys cannot secure a weak signing pipeline, what remains disputed, and what exchange users should ask.
Written by AI. Rachel "Rach" Kovacs

Bitget says an attacker stole about $387.5 million from the crypto exchange on September 24 after compromising a backend wallet system and feeding false transaction data into its authorization process.
The company says its private keys remained secure. That sounds reassuring until you consider what those keys actually did: they signed transfers generated by a system the attacker had deceived.
This breach is a useful demonstration of where exchange security can fail after the cryptography does its job. Offline keys, multisignature wallets and hardware security modules can protect signing credentials. They cannot independently decide whether the transaction placed in front of them represents a customer withdrawal, a treasury movement or an attacker wearing a convincing software moustache.
The Signing Pipeline Approved the Theft
Bitget detected unauthorized transfers at 18:31 UTC. CEO Gracy Chen said the attacker had compromised “a critical backend system within our wallet infrastructure,” spoofed transaction data and triggered the exchange’s authorization process. The company engaged Mandiant and SlowMist to investigate, according to an account of its incident notices.
CNBC reported that the theft involved 19 transfers, as summarized by The Next Web. Bitget initially put the loss at $351.6 million, then raised it to $387.5 million after adding assets on Zcash and TRON that its first count had missed. The company said this reflected a fuller inventory of the original incident rather than additional theft after containment.
The available account therefore points to a failure in the decision layer between a withdrawal request and a valid signature. If compromised software can rewrite destinations, amounts or the context shown to approvers, intact private keys may faithfully authorize a fraudulent transfer. The controls have protected the pen while an attacker has replaced the paperwork.
That inference has limits. Bitget has identified the affected backend system, but SecurityWeek reports that the company had not established how the attacker entered it. Until a root-cause report explains the initial access, privilege escalation and approval controls, outsiders cannot determine whether the central weakness involved software, credentials, a vendor, an employee account or some combination.
The Wallet Labels Do Not Fully Agree
Bitget says the incident reached parts of its hot and warm wallet layers and left its cold wallets untouched. Arkham Intelligence’s preliminary analysis produced a complication: it identified a wallet holding roughly $153 million in stolen XRP as a Bitget cold wallet, The Register reported. Arkham also estimated that $228 million left Bitget-controlled wallets during an 18-minute period.
Those accounts could differ because Bitget and Arkham classify the wallet differently, because the ownership tag was wrong or because the company’s first description was incomplete. The current information cannot settle which explanation is correct.
For customers, “cold wallet” should describe more than whether a private key touches the internet. An exchange should also explain how transactions reach that key, what independent checks validate the destination and amount, how many people or systems can approve a transfer, and whether approvers see transaction details through a separate trusted channel. A cold key connected to a compromised instruction pipeline can still produce a perfectly valid blockchain transaction.
North Korea is a Strong Lead, Not a Settled Verdict
Chen said investigators found IP behavior associated with VPN services used by a North Korean group, along with matching on-chain patterns. She did not name a group, and Bitget has not published the underlying technical evidence.
Blockchain analytics firm Elliptic separately assessed a North Korean connection as “highly likely.” Its reasoning included links between assets taken from Bitget and ether from an earlier theft attributed to North Korea, plus contact with addresses used to launder proceeds from the 2025 Bybit heist. That convergence makes the attribution plausible. Shared infrastructure and fund flows can provide strong evidence, but they do not carry the same weight as a public forensic account connecting the intrusion itself to a named operator.
The comparison with Bybit shows the difference in confidence. The FBI attributed the roughly $1.5 billion Bybit theft of February 2025 to North Korea. No government agency had publicly made an equivalent finding about Bitget as of September 26, and Bitget’s entry path remained under investigation.
History raises the prior probability without proving this case. TRM Labs estimated in April that North Korean operators had stolen more than $6 billion in cryptocurrency since 2017 and accounted for 76% of stolen crypto value through that point in 2026. Previous lucrative exchange attacks attributed to the country include raids on Bybit, DMM Bitcoin and WazirX.
That record explains why investigators looked toward Pyongyang quickly. It should not turn “resembles previous activity” into a synonym for confirmed attribution. The strongest current formulation is narrower: Bitget and Elliptic see indicators consistent with North Korean operations, while the public evidence remains incomplete.
A Protection Fund Transfers the Immediate Loss
Chen says customer balances remain accurate because Bitget’s User Protection Fund, valued at more than $464 million, can absorb the theft. Withdrawals were paused for security checks while deposits and trading continued. The company has said the fund consists of 5,500 bitcoin, so its dollar value moves with bitcoin’s price until assets are used or converted.
The fund has grown substantially. It stood at $300 million in 2023, according to Decrypt’s account. A reserve large enough to cover a nine-figure incident can prevent customers from becoming direct creditors of the disaster. It also concentrates several questions in one place: how quickly can the fund be liquidated, what replenishment policy applies after a payout, and how independently can users verify its assets and liabilities?
“User funds are safe” describes the promised effect on account balances. It does not mean the loss disappeared. Bitget or its reserve bears it, and a large payout would leave a smaller cushion unless recovered funds or company assets replenished the fund. The fund’s bitcoin concentration also creates market risk because the liability is measured across several stolen assets while the reserve’s dollar value floats with one asset.
Bitget has offered a 5% bounty for funds that participants help freeze or recover. Some issuers can blacklist stolen stablecoins, but ether and other assets without a central issuer cannot be frozen in the same fashion. The attacker had already converted much of the haul from Ethereum-compatible chains into 67,982 ETH, according to Lookonchain.
Conversion carries friction. A wallet highlighted by the pseudonymous researcher DCF GOD spent $19.67 million in USDT0 to acquire 7,111 ETH in six minutes, paying roughly 5% above market through UniswapX and 1inch Fusion. That does not prevent laundering, but it shows why thieves race to consolidate mixed assets into liquid tokens even when the exchange rate is ugly. Speed can be worth more to an attacker than getting a tidy price.
What Exchange Customers Can Ask Now
Individual customers cannot audit an exchange’s wallet backend, and moving assets into self-custody introduces its own risks, including lost recovery phrases, malicious approvals and irreversible mistakes. The practical response depends on how much custody work a user can safely handle.
People keeping assets on a centralized exchange can still ask better questions. Does the platform publish reserve addresses and liabilities? Is its protection fund segregated and independently verifiable? Does it cap hot-wallet exposure? Do withdrawal approvals verify transaction details through a system separate from the software creating the transaction? How did it replenish reserves after previous incidents?
Bitget’s eventual root-cause report will be more useful if it answers those questions with architecture and control changes rather than another assurance that the keys were safe. The September 24 transfers show why the next security test begins one step earlier: who, or what, gets to tell a protected key what to sign?
More Like This
A Four-Step Framework for Automating Work With Claude
A YouTube creator's four-step Claude automation framework is drawing attention. Here's what works, what needs scrutiny, and what it means for your actual workweek.
Claude Fable 5 Return, OpenAI Jalapeño Chip, and AI Espionage
Claude Fable 5 signals a return, Anthropic accuses Alibaba of mass model distillation, OpenAI unveils its Jalapeño chip, and Gemini 3.5 Pro disappoints.