Bitget confirms $351.6M hot wallet breach, User Protection Fund covers loss

Bitget confirmed a $351.6 million breach of a slice of its hot and warm wallet layers late on Thursday, September 24, and says its User Protection Fund will absorb the entire loss. The exchange has paused withdrawals while it investigates, and on-chain analysts have pointed to North Korea’s Lazarus Group as a likely culprit.

  • Bitget’s security systems flagged unauthorized transfers at 18:31 UTC on September 24, totaling roughly $351.6 million.
  • The exchange’s User Protection Fund holds more than $464 million, exceeding the shortfall by over $112 million.
  • On-chain investigator Specter and analyst Conor Grogan have pointed to the Lazarus Group as the likely attacker.
  • $351.6M assets affected in the hot and warm wallet breach
  • $464M User Protection Fund balance, exceeding the loss
  • 18:31 UTC detection time on Thursday, September 24
  • $1.1B stolen crypto industrywide across 212 incidents in H1

According to CryptoPotato reported, Bitget said its monitoring systems caught unauthorized outbound transfers from a portion of its hot wallets at 18:31 UTC on Thursday, September 24. The exchange put the total affected assets at approximately $351.6 million. Withdrawals remain paused while the incident is under review, but Bitget says customer balances will not be reduced.

Attacker spoofed backend authorization, cold wallets untouched

Bitget CEO Gracy Chen said the exchange operates a three-tier wallet architecture, and the breach affected only a slice of the hot and warm layers. Cold wallets, which hold the majority of exchange assets, were not touched, according to Chen’s account posted on Bitget’s official X account.

Chen said the attacker breached a backend system within Bitget’s wallet infrastructure. The intruder then spoofed transaction data to trick the exchange’s authorization process into releasing funds.

Chen ruled out a compromise of private keys, narrowing the scope of what went wrong inside Bitget’s systems. She said containment has been confirmed and that no further unauthorized transfers are possible, with emergency protocols having flagged and reported the affected addresses within minutes of detection.

User Protection Fund covers loss with $112 million to spare

Bitget says its User Protection Fund currently holds more than $464 million, well above the $351.6 million shortfall from Thursday’s breach. The exchange plans to draw on that fund to make customers whole rather than socialize the loss across the platform.

We will not run from this, and every dollar will be accounted for.

Gracy Chen, CEO of Bitget, in a post on X

Chen said a full incident report covering root cause and corrective steps would follow within 24 hours of the initial notice, according to her post on X.

Lazarus Group suspected, following a pattern from 212 incidents this year

On-chain investigator Specter claimed the North Korea-linked Lazarus Group carried out the attack, in a post on X. Analyst Conor Grogan backed that assessment, noting a deviation from the group’s usual timing.

“Generally they do these on the weekends but perhaps they had a limited window for the exploit and didn’t want to risk it,” Grogan wrote.

The Bitget incident adds to a heavy year for crypto exploits. Roughly $1.1 billion was stolen across 212 incidents industrywide in the first half of the year, with more than half of that sum traced back to the Lazarus Group, according to the figures cited in CryptoPotato’s reporting.

The BlockWest read. The reserve math here matters more than the breach itself: a $464 million protection fund covering a $351.6 million shortfall with room to spare is the kind of buffer most exchanges do not disclose until forced to. If Bitget’s promised root-cause report actually details how backend authorization was spoofed, it becomes a template other exchanges will be pressed to match, not just a postmortem.

Bitget has not yet published the full incident report Chen promised within 24 hours of the initial notice, leaving the precise backend vulnerability and any additional corrective steps still undisclosed as withdrawals remain paused.