Skip to content

Bitget $351.6M Hack Probe Points to Backend Breach as Private-Key Leak Is Ruled Out

Bitcoin3 min read

Bitget $351.6M Hack Probe Points to Backend Breach as Private-Key Leak Is Ruled Out

Bitget’s preliminary investigation into the September 24 hack has focused on its backend wallet infrastructure. The exchange stated that there were no private keys exposed during the hack. An estimated $351.6 million was hacked in the breach. However, deposits and trading on the exchange continued; only withdrawals were suspended during the incident.

Bitget reported that the withdrawals were unauthorized at 18:31 UTC, and emergency measures were taken within a few minutes. The exploit impacted some hot and warm wallets on the exchange, but the cold wallets remained unbreached.

Bitget also stated that the balances were correct, and the loss was covered by the User Protection Fund, which had a balance of more than $464 million. Authorities and blockchain security firms also took notice.

The exchange reported that those abnormal destination addresses were flagged and relayed. Withdrawals have no fixed reset time and will be opened only after a security review.

In a livestream Q&A, Bitget CEO Gracy Chen shared that the team had ruled out the possibility of private key leakage in Bitget’s wallet architecture, and that attackers had entered Bitget’s exchanges and transferred out assets.

A preliminary analysis shows that the core backend wallet service has been compromised, and the fraudulent transaction has already reached the approval-signature stage. However, Bitget has yet to provide further technical details. This will remain until the final investigative determination.

Read More: $320M Bitcoin Hack: What Really Happened to Liquid Network?

On-chain estimates differ slightly from Bitget’s, as Lookonchain believes the stolen portfolio to be worth $356.8 million at the price in the article. The largest position was 102.93 million XRP (approximately $157.48 million), followed by 31,890 ETH (approximately $85.75 million).

Other tracked assets were USDT, USDC, USD₮0, XAUt, BNB, AVAX, and TRX. This is due to different methods of valuing and recording a position, not due to an actual revision of Bitget’s estimated loss.

However, the attribution to North Korean hackers was not confirmed. Chen said investigators had identified IP addresses linked to widely used VPN services associated with the North Korean hacking group but that the overall pattern fit.

Bitget itself did not identify the attacker, nor did any government agency publicly attribute the hack to North Korea at the time of the hack.

Withdrawals remain suspended as the security review is continuing, although no official timeline for resuming withdrawals was provided. Bitget stated deposits and trading were still functional as the engineering teams continued to fix affected systems and security controls.

Read More: FBI Crypto Crime Forum Targets Scams, Hacks and North Korean Threats

Chen said that some of the stolen assets had been recovered, but he did not specify an amount, and no figure has been verified by journalists.

Bitget has promised to publish a complete incident report, including root cause and remediation, within 24 hours of its September 24 security notice. Until such a report containing technical evidence is released, we should consider the backend compromise and potential North Korean involvement as initial findings only.

The NewsDIO Briefing

One email each morning with the stories that matter.

Join the discussion

Your email address is not published. Required fields are marked.