Bitget raised its estimate of Thursday's security breach to $387.5 million on Friday, up from the $351.6 million first disclosed, after tracing additional stolen assets on Zcash and TRON. The exchange says attackers spoofed transaction data to trick its own authorization system into approving fraudulent transfers, and CEO Gracy Chen suspects a North Korean link.
Bitget confirmed on Friday that $387.5 million was transferred to attacker-controlled addresses during Thursday's breach, about $35 million more than the exchange first disclosed. Bitget said the revised figure reflects a more complete accounting of transfers on Zcash and TRON, not new unauthorized activity.
How the theft moved
Bitget's security systems detected unauthorized transfers out of some of its hot wallets at 18:31 UTC on September 24. Within about an hour, on-chain investigators had tallied roughly $183 million in stablecoins, Ethereum, and other crypto assets sliding out of wallets tied to the exchange.
Analyst DCF GOD then flagged a fresh wallet that spent $19.67 million in USDT0 to buy 7,111 ETH in six minutes through decentralized exchanges. It reportedly paid as much as 5% above market prices to do so. Bubblemaps separately reported roughly $180 million moving from Bitget wallets to a common receiving address before it split across several wallets. The single biggest piece of the haul turned out to be roughly 103 million XRP, worth about $157 million.
A backend compromise, not stolen keys
Chen said attackers compromised a critical backend system that manages wallet operations, supplying false transaction data to trigger the exchange's own authorization process. Private-key theft was reportedly ruled out, though how attackers entered the backend remains undisclosed.
The breach touched addresses across Ethereum Virtual Machine networks, the XRP Ledger, Zcash and TRON, with stolen assets including XRP, Ether, USDT, Zcash, USDC, USDT0, BNB and AVAX. Bitget's User Protection Fund, which holds more than $464 million, will cover the loss, Chen said, so customer balances stay intact even though the money itself is gone.
North Korea suspected, not confirmed
Chen pointed to Pyongyang, though carefully. According to Decrypt: "identified some IP addresses that match the VPN choices by a certain DPRK group". Coinpedia noted similarities to the February 2025 Bybit hack, including manipulated approvals, rapid asset conversion, wallet splitting and the use of THORChain — though those similarities don't independently identify the attackers.
Bitget has paused withdrawals and launched a bounty program to incentivize freezing or recovering the assets. It has also promised a withdrawal plan by September 26 at 04:00 UTC. The exchange says the vulnerability behind the fraudulent approvals is fixed, but it still hasn't disclosed how attackers reached the backend system in the first place.
Sources: Cointelegraph.com News, Decrypt, Coinpedia Fintech News
Trading involves risk.