Press play to start listening
Cryptocurrency exchange Bitget has confirmed that attackers stole approximately $351.6 million after gaining unauthorized access to part of its wallet infrastructure.
The incident was detected at 18:31 UTC on September 24, 2026, when Bitget’s security systems identified unauthorized transfers involving several hot wallets. The exchange suspended withdrawals, flagged the receiving addresses and contacted law enforcement and blockchain security companies.
Bitget said deposits and trading remained available. It also stated that customer balances were accurate and its cold wallets had not been affected.
According to Bitget CEO Gracy Chen, the stolen amount is covered by the exchange’s User Protection Fund, which held more than $464 million when the incident occurred.
Bitget Says Its Internal Systems Were Breached
During a live broadcast on X, Chen described the incident as a direct breach of Bitget’s systems or servers. She said the attackers transferred funds directly rather than forging withdrawal requests from customer accounts. Chen also said the attackers did not obtain users’ private keys or compromise Bitget’s cold wallets.
Bitget has not explained how its systems were accessed or how the attackers were able to authorize transfers from the affected wallets. An investigation into the entry method and transfer process remains underway.
Bitget CEO Addresses Inside Job Claims
Chen also addressed speculation that the theft may have involved a Bitget employee. She said the company does not currently believe it was an inside job, although investigators have not completely ruled out the possibility that an employee assisted the attackers. Chen described that possibility as “quite low” and said she hoped no insider was involved.
She acknowledged that insider threats have affected several cryptocurrency and blockchain companies and noted that Bitget employs approximately 2,000 people. Bitget has not published evidence linking any employee to the breach.
The company’s initial statement said the incident affected a limited number of hot wallets and part of its warm-wallet layer. This does not necessarily conflict with Chen’s statement that wallet keys were not stolen. An attacker could abuse internal wallet-management systems without extracting the underlying keys, although Bitget has not confirmed that this is what happened.
Nevertheless, withdrawals were suspended to prevent the feature from being misused while Bitget examined its systems. Chen said during the broadcast that withdrawal services would return after the security review, but she did not provide a firm reopening time.
CEO Suspects Lazarus Group
Chen said Bitget believes the Lazarus Group, a North Korean state-backed hacking operation, was responsible for the theft. However, at the time of releasing this story, no technical evidence supporting that attribution has been published.
Lazarus has previously been blamed for major cryptocurrency thefts, including attacks against centralized exchanges such as the Bybit hack in 2025, in which the group stole $1.4 billion, blockchain services and individual cryptocurrency holders.
Their primary objective is stealing funds to support North Korea’s heavily sanctioned economy, which struggles under international financial restrictions.
Chen said she had encountered the group before when approximately $80,000 was stolen from one of her personal wallets outside Bitget. Her previous experience does not by itself establish who carried out the latest attack.
User Protection Fund Expected to Cover Loss
Bitget says its User Protection Fund is large enough to cover the entire reported loss. With more than $464 million held in the fund, its stated value exceeded the stolen amount by approximately $112.4 million at the time of the announcement.
The exchange has not said whether it will immediately draw from the fund, how the fund’s value is calculated or whether any customers will need to submit claims. It maintains that customer assets and account balances remain protected.
Bitget also said the affected transfer addresses had been identified and reported; meanwhile, funds moved through public blockchains can be tracked, but recovery depends on whether assets reach cooperating exchanges, remain identifiable or are frozen before being converted or passed through laundering services.
A full incident report containing the cause of the breach and corrective actions was promised within 24 hours. Until that report is published, the exact vulnerability exploited and the evidence connecting the operation to Lazarus remain unknown.