Bitget Loses $387 Million After Attackers Hijack Its Own Approval System
Attackers drained up to $387.5 million from Bitget's hot and warm wallets on September 24 by injecting fake internal transfer requests into the exchange's own authorization layer. Circle and Tether froze just $318,000 of the stolen funds; 102.93 million XRP and over 63,000 ETH remain in attacker-controlled wallets, with North Korean state hackers suspected.

Original analysis, verified sources, real-world experience
What happened
$387.5 million left Bitget's hot and warm wallets on September 24, according to Decrypt and BeInCrypto ID. Initial reports from DiarioBitcoin put the figure at $351.6 million; the number rose as blockchain trackers finished their analysis.
Bitget suspended withdrawals immediately after the breach. The exchange's CEO stated publicly that the attack's fingerprints match patterns attributed to North Korean state hacking groups, though the attribution remains a working hypothesis rather than a confirmed fact. Bitget Wallet, the self-custody product, operates on separate infrastructure and was not affected, CriptoNoticias reported.
How the attack worked
The phrase "hot wallet key compromised" that circulated early is misleading. CriptoNoticias reports that Bitget's own post-incident disclosure ruled out cryptographic key theft. The actual vulnerability was in the system that decides which transactions receive authorization for signing, not in the private keys themselves.
The attacker injected fake internal transfer requests into Bitget's approval workflow, as Decrypt describes. The exchange's own infrastructure validated those requests and released funds. The private keys were never exfiltrated; the authorization layer was the point of failure.
This distinction matters operationally. A key-compromise attack requires stealing and using private material off-chain. An authorization-layer attack corrupts the decision logic inside the exchange's operational systems, demanding either deep access to internal infrastructure, a social engineering path to someone with approval authority, or a compromise of the software that generates and validates transaction requests. The damage looks like a legitimate internal operation until blockchain analysis reveals the destination wallets.
IP addresses found in the attack trace match VPN infrastructure used by North Korean hacker groups, according to CriptoNoticias. That finding remains circumstantial until confirmed by a law enforcement body or independent forensic firm.
What user funds are at risk
The asset breakdown tells the recovery story bluntly. Uzmancoin reports that 102.93 million XRP, worth roughly $157.5 million, was among the stolen assets. DiarioBitcoin notes that over 63,000 ETH remained in separate attacker wallets after the initial drain.
The stablecoin response was fast but limited. CoinDesk reports that Circle and Tether blacklisted a wallet holding approximately $318,000 in USDT and USDC combined. That represents less than 0.1% of the total stolen. Ether and XRP have no central issuer capable of freezing balances. The majority of stolen funds sits entirely outside the reach of any freeze mechanism.
Users with custodial balances on Bitget face two distinct risks: direct exposure if their wallet addresses were among those drained, and liquidity risk if withdrawals remain suspended during a volatile market period. Neither risk has a clear resolution timeline at this stage.
Pattern recognition
The combination of authorization-layer bypass and suspected North Korean involvement places this event in a well-documented attack family.
The Bybit exchange hack earlier in 2026, which resulted in $1.4 billion in losses, was also attributed to North Korean state actors and involved manipulation of the signing and approval process rather than direct key extraction. That incident demonstrated that sophisticated attackers now target the governance layers of exchange infrastructure specifically because the attack surface is harder to monitor than key storage. An attacker who corrupts authorization logic generates transactions that look valid at every checkpoint until funds are already gone.
The 2022 Ronin Bridge hack, attributed by the U.S. Treasury to the Lazarus Group, followed a similar logic: the attacker acquired enough signing authority, through a combination of compromised validator keys and social engineering, to approve withdrawals at scale. Private keys were involved in that case, but the core failure was the same: a small number of trusted signers controlled a disproportionate share of authorization power, and once those signers were compromised, the system behaved correctly while draining itself.
What shifts with each iteration is scale and operational depth. Attackers attributed to North Korea have consistently targeted assets that move freely past stablecoin freeze mechanisms. XRP and ETH, which dominate the Bitget losses, are exactly those assets.
What to do now
If you hold funds on Bitget, treat the withdrawal suspension as an ongoing situation requiring daily monitoring, not a resolved one. Suspensions can lift quickly or persist for weeks depending on the exchange's liquidity position and regulatory obligations.
For assets you can still access, moving them to self-custody removes custodial risk entirely. Bitget Wallet, the non-custodial product, was confirmed unaffected, but any self-custody solution works. Our standard position after any major exchange incident: assets you do not need for active trading should not sit on a centralized exchange.
Check your on-chain approvals. If you have interacted with any Bitget-linked smart contracts for on-chain products, verify your active permissions through a revocation tool and remove any approvals granted to Bitget-related contract addresses. This step matters regardless of whether your exchange balance is affected.
Watch on-chain tracking publications for any published list of addresses linked to the breach. If a deposit address you used appears on such a list, document your transaction history and contact Bitget support with that evidence.
Set aside the attribution question for now. The CEO statement and VPN IP match are consistent indicators of North Korean involvement, but forensic confirmation typically follows weeks or months after the initial incident. For users, the actionable question is fund recovery, not attacker identity.
FAQ
Was Bitget Wallet, the self-custody app, affected by the hack?
No. Bitget Wallet confirmed through its official channels that the breach did not affect its systems. The hack targeted Bitget's centralized exchange hot and warm wallets, which are separate infrastructure from the self-custody product.
Why could Circle and Tether only freeze $318,000 when nearly $387 million was stolen?
Circle and Tether can only freeze assets they issued, specifically USDC and USDT. The bulk of the stolen funds consisted of XRP and ETH, which have no central issuer with freeze authority. CoinDesk confirmed the blacklisted wallet held approximately $318,000, less than 0.1% of the total stolen.
If cryptographic keys were not stolen, how did the attacker drain the wallets?
Bitget's own disclosure ruled out key theft. According to CriptoNoticias, the attacker compromised the system that decides which transactions get approved for signing, then injected fake internal transfer requests that the exchange's infrastructure processed as legitimate operations.
This article is for educational purposes and is not investment advice. Cryptocurrencies carry high risk. Only trade with funds you can afford to lose.
CoinMagnetic Team
Crypto investors since 2017. We trade with our own money and test every exchange ourselves.
Updated: September 2026
Follow our analysis on Telegram
We publish analysis, digests and forecasts on our Telegram channel.
Follow the channel

