Particle.news

Bitget Hack Drains $387.5 Million, Withdrawals Suspended

A backend wallet-authorization breach that falsified transfer approvals leaves withdrawals frozen with customer balances covered by Bitget’s User Protection Fund.

Overview

  • Bitget detected unauthorized transfers on Sept. 24 after attackers spoofed internal approval data to move assets from the exchange’s hot and warm wallets.
  • The company’s later accounting raised the total affected to about $387.5 million after investigators found additional transfers on Zcash and TRON.
  • Bitget says private keys and cold wallets were not exposed and that its User Protection Fund, reported at roughly 5,500 BTC, will cover customer balances while forensic work continues.
  • On-chain analysts traced large XRP and ETH holdings to attacker-controlled addresses, and investigators report the thief has begun consolidating funds and withdrawing sums through other exchanges.
  • Bitget has engaged Mandiant, SlowMist and law enforcement to trace and recover assets, and preliminary IP and on-chain patterns point to North Korea–linked groups though formal attribution remains unconfirmed.