The incident began over the weekend when Bitget's security system detected unusual transactions from its hot and warm wallet infrastructure. The exchange initially estimated 351.6 million USD in affected assets, but later raised the figure to 387.5 million USD after reviewing transactions on the Zcash and TRON networks. The Block reports this as one of the largest crypto thefts in 2026.
Bitget confirmed that private keys were not stolen, cold wallets remained secure, and customer account balances were unaffected. However, the incident necessitated a temporary suspension of withdrawals for a full infrastructure inspection.
This incident was not a typical attack involving the theft of private keys for direct fund transfers. Bitget reported that attackers infiltrated a critical backend system within the wallet infrastructure, then falsified transaction data. This fabricated data entered the approval process, leading the exchange's authorization system to process illegal asset transfers as valid transactions. The problem originated in the transaction control and approval layer, not with the cryptographic keys protecting assets.
The incident raises concerns about how hackers bypassed an exchange's control systems. While private key theft typically prompts a focus on key management, transaction approval permissions, and cold wallet use, Bitget's case indicates hackers tricked the internal system into validating an unauthorized transaction.
Cybersecurity firm Hypernative suggests the vulnerability lies in the transaction approval system relying on recipient address and amount information from a backend service, rather than independently verifying it. Essentially, hackers did not "steal the safe's key," but rather tricked the management system into opening the safe and transferring funds itself. This raises a critical question for centralized exchanges: private key control alone is insufficient if the software layer preceding the transaction approval process can be manipulated.
TRM Labs, a financial crime and blockchain investigation firm, analyzed that funds were withdrawn from multiple networks: Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain, and Base. Affected assets included ETH, XRP, BNB, AVAX, USDT, USDC, and other tokens.
![]() |
The Bitget exchange application on a phone is placed in front of an image of CEO Gracy Chen. *Photo: Tat Dat* |
Immediately upon discovery, Bitget temporarily suspended all withdrawals, emphasizing it was a security measure, not a liquidity issue. Trading and deposit activities continued, with customer account balances remaining intact. Bitget stated its user protection fund, holding over 464 million USD, is sufficient to cover the 387.5 million USD loss. However, experts noted that the entire fund is not immediately available cash.
Bitget suspects North Korean hacker groups are involved, though this is not the investigation's final conclusion. CEO Gracy Chen stated that IP, behavioral, and data analysis indicates the attack method is "highly consistent" with North Korean groups. The company also noted similarities between some money laundering addresses and those used in past attacks.
TRM Labs remains more cautious, noting that addresses linked to the Bitget incident overlap with wallets used in past hacks attributed to North Korea, including the Bybit incident. However, TRM has not officially blamed North Korea for the Bitget incident, stating that more technical evidence is needed to solidify this connection.
The ongoing investigation involves Mandiant, a Google Cloud cybersecurity company, and SlowMist, a cybersecurity firm with experience tracking crypto exchange hacks, alongside authorities. The priority is tracing the flow of funds.
After identifying the attack vector, Bitget stated the vulnerability has been patched and the incident isolated. The exchange also launched a Recovery Bounty program, offering a 5% reward for direct assistance in freezing or recovering affected assets, subject to program conditions.
Established in 2018, Bitget is a global crypto exchange offering diverse asset trading services. It ranks as the 6th largest crypto exchange by trading volume, serving tens of millions of users worldwide. Bitget has maintained an official community and support channel for the Vietnam market since 2022.
Hot wallets, connected to the internet, are convenient for frequent crypto transactions and withdrawals but carry higher security risks than cold wallets. Warm wallets strike a balance, able to connect online for transactions but more isolated and controlled than hot wallets.
Tieu Gu
