Intel Hub

Threat intel

Bitget lost $351.6 million after attackers spoofed what its approval system saw.

Bitget says suspected North Korean hackers drained about $351.6 million from hot and warm wallets by manipulating transaction data shown to its authorization process. Private keys were not stolen.

Cryptocurrency exchange Bitget disclosed on September 25 that attackers stole about $351.6 million from its hot and warm wallets. The exchange suspended all withdrawals after its security systems flagged unauthorized transfers on Thursday evening, according to BleepingComputer, CNBC and SC Media.


Bitget says the attackers compromised a backend wallet system and manipulated the transaction data presented to its authorization process, which then approved the transfers. The exchange says private keys were not stolen. That distinction matters: the signing controls worked as designed, but they were fed falsified inputs.


Attribution points to North Korea. Bitget's CEO called involvement "very likely", citing IP addresses that matched VPN services associated with a North Korean hacking group. Elliptic described the link as highly likely. TRM Labs said in its own write-up that it has not yet definitively attributed the exploit.


Bitget is working with law enforcement, Mandiant and SlowMist, and says its User Protection Fund, which holds more than $464 million, will cover the losses.


Why it matters. Attacks that alter what an approver sees, rather than stealing keys, sit outside controls built around key custody. Defenders running custody or payment workflows should verify transaction details on an independent path before approval, for example by re-deriving amounts and destinations from a separate trusted source. They should also isolate and closely monitor backend wallet services, alert on approvals whose payloads differ from originating requests, and enforce withdrawal limits and cooling-off delays on hot wallets.

Sign-in required.

The full encrypted event log and the mitigation steps are available after sign-in.