Zero Day Room
Live
Threats

Bitget resumes withdrawals after $387.5 million North Korean

Bitget confirmed a $387.5 million crypto theft by suspected North Korean hackers, exploiting a backend wallet system.

Threats: Bitget confirmed a $387.5 million crypto theft by suspected North Korean hackers, exploiting a backend wallet system

Bitget has resumed Bitcoin withdrawals after a week-long suspension caused by a $387.5 million theft. The cryptocurrency exchange attributes the sophisticated attack to suspected North Korean hackers who exploited a critical backend system.

Unauthorized transfers began on September 24, targeting a limited number of the exchange's hot and warm wallets. Security systems flagged the activity, leading to the immediate suspension of Bitcoin withdrawals. CEO Gracy Chen stated the hackers breached a backend system within Bitget's wallet infrastructure. They used it to spoof transaction data, triggering the exchange's own authorization process to move funds. The incident affected multiple assets across several blockchains, including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base.

Chen provisionally attributes the operation to North Korean actors based on observed IP addresses and attack methods. This attribution remains the company's claim and has not been publicly confirmed by an independent authority. North Korean state-sponsored groups have a long history of major crypto thefts. British blockchain analytics firm Elliptic estimated in February 2025 that these hackers have stolen over $6 billion in crypto assets since 2017.

The theft estimate was revised upward on September 25. Initial on-chain analysis pointed to a loss of $228 million across seven blockchains. Deeper investigation, which included tracking transfers on the Zcash and Tron blockchains, increased the figure to $387.5 million. Analysts at Lookonchain estimate that 67,982 ETH, valued at approximately $183 million, were converted from Ethereum-compatible networks.

Impact and response

Bitget states that user account balances were unaffected and that its separate, self-custody Bitget Wallet product was not compromised. The company claims private keys were not exposed and that its cold wallets remain secure. "The incident remains contained, and no further unauthorized transfers are possible. User funds are unaffected throughout this process. Trading and deposits continue to operate," Bitget said.

The financial impact is being covered by the exchange's Protection Fund, which it states exceeds $464 million. This provides a margin of roughly $76.5 million, or about 20%, over the identified loss. A significant portion of this fund is held in bitcoin. Bitget is working with security firms Mandiant and SlowMist, alongside authorities and blockchain projects, to trace and freeze stolen assets. Some assets have already been frozen with help from other platforms and stablecoin issuers.

The company has launched a Recovery Bounty Program, offering a reward equivalent to 5% of any funds frozen or recovered through eligible voluntary intervention. A public dashboard tracks addresses controlled by the hacker.

Withdrawal resumption timeline

Bitget has published a phased schedule for restoring full withdrawal services, having addressed the exploited security vulnerability. The timeline for resumption was announced by September 26, as required.

Asset / NetworkResumption Date & Time (UTC)
ETH (Ethereum, BSC, Arbitrum, Base, Optimism)September 29 at 8:00 UTC
USDT (Ethereum, BSC, Solana, Tron)September 30 at 8:00 UTC
Other tokens / Fiat / P2P assetsOctober 2 at 8:00 UTC

Estimate revisions and scope

The scale of the theft became clearer as investigators followed the digital trail. The final revised total of $387.5 million reflects the inclusion of previously overlooked transactions on the Zcash and Tron networks. The stolen assets included a wide array of tokens.

Affected assets include ETH, XRP, BNB, AVAX, USDT, USDC, ZEC, USDT0, XAUt, and TRX. Bitget will resume withdrawals for ETH on September 29 at 8:00 UTC, with other assets following in the coming days.

Related coverage

More from Threats