Bitget Loses $351.6 Million in Hot Wallet Hack, Lazarus Group Suspected
Cryptocurrency exchange Bitget has confirmed a major security breach, with attackers siphoning approximately $351.6 million in digital assets from its hot and warm wallets.

Cryptocurrency exchange Bitget has confirmed a significant security breach affecting approximately $351.6 million in assets after unauthorized transfers were detected in parts of its hot and warm wallet infrastructure. The incident was identified at 18:31 UTC on September 24, 2026, prompting the security team to activate emergency response procedures within minutes. Bitget stated that its offline cold wallets remained secure and that customer account balances continue to accurately reflect their holdings. The compromise was contained within specific segments of Bitget’s three-tier wallet architecture, according to an official security notice.
While the exchange has not yet published a complete inventory of stolen assets, on-chain observers tracked movements involving ETH, BNB, AVAX, USDT, and USDC. Early estimates placed suspicious transfers between $174 million and $183 million before Bitget established the full $351.6 million exposure. Bitget temporarily suspended withdrawals while investigators reviewed its wallet systems and determined the extent of the risk to its infrastructure. Deposits and trading services remained available during the investigation.
The exchange reported that it identified and flagged the recipient addresses, informed law-enforcement agencies, and engaged blockchain-security companies to trace the stolen funds. Chief executive Gracy Chen indicated that the loss would be covered by Bitget’s User Protection Fund, which the company values at over $464 million, leaving a buffer of roughly $112.4 million above the estimated loss. This assurance highlights the critical need for verifiable and accessible protection reserves during large exchange compromises.
During a live question-and-answer session, Chen suggested that preliminary evidence pointed to IP addresses resembling VPN infrastructure previously associated with North Korean threat groups. She also noted that the activity followed patterns seen in earlier North Korean operations, raising suspicion around the Lazarus Group. However, official attribution remains unconfirmed, and Bitget has stated it will not speculate further until its investigation is complete. This potential link is significant given North Korean actors were blamed for the approximately $1.5 billion Bybit theft in 2025.
Chen further indicated that the attackers transferred assets directly after gaining access to Bitget systems, rather than submitting fraudulent customer withdrawal requests. Preliminary findings reportedly suggest the intruders did not obtain private keys and may have compromised a critical backend component supporting wallet services. Investigators are examining whether a third-party tool or a supply-chain attack enabled forged transfer instructions to reach authorized signing infrastructure.
Bitget has promised hourly updates through official channels and a full incident report within 24 hours, which is expected to cover the root cause, affected systems, and corrective actions. Until that report is released, the precise initial-access vector, persistence mechanism, and control failures remain unknown. Customers are advised to rely only on verified Bitget communications, remain alert to phishing messages exploiting the withdrawal pause, and avoid sharing credentials or signing unsolicited wallet requests.
The incident underscores the persistent threat posed by sophisticated actors to the cryptocurrency ecosystem. The scale of the theft and the potential involvement of a state-sponsored group like Lazarus Group highlight the need for continuous vigilance and advanced security measures within digital asset exchanges.