Overview
- Bitget detected unauthorized transfers on Thursday and quickly activated emergency protocols, later confirming about $351.6 million moved from parts of its hot and warm wallet layers and pausing withdrawals.
- Independent on-chain trackers first flagged roughly $170–$183 million moving to a fresh address, but Bitget’s internal reconciliation raised the total exposed to about $351.6 million.
- The company says attackers compromised a backend wallet-management system and forged transaction data to trigger normal authorizations, and Bitget asserts private wallet keys and cold storage were not stolen.
- Bitget has flagged recipient addresses, notified law enforcement and security firms, and says its User Protection Fund of more than $464 million covers the reported loss while deposits and trading remain open.
- Attribution to a North Korea–linked group is being investigated but not proven, and the market will watch Bitget’s promised incident report, asset-tracing results, and the timeline for safely reopening withdrawals.