Attackers who breached Bitget's hot wallets on Thursday drained 102,926,478 XRP worth around $157.48 million, the single largest asset loss in the $351.6 million exploit. Bitget says the breach came through a compromised backend system rather than stolen private keys, and its $464 million-plus User Protection Fund will cover customer losses while investigators probe a possible North Korea link.
XRP took the biggest hit of any asset in Bitget's $351.6 million hack, with attackers draining 102,926,478 XRP worth around $157.48 million from the exchange's hot wallets. Bitget detected the unauthorized transfers at 18:31 UTC on Thursday and activated its emergency response protocols.
XRP Suffers the Largest Loss
The stolen XRP's value was almost twice that of ether, the second-largest asset affected. Bitget lost 31,890 ETH worth $85.75 million, while USDT and USDC losses reached $34.75 million and $21.06 million. Other assets drained included 19.67 million USDT0, 3,000 XAUt, 12,719 BNB, 821,012 AVAX and 20.59 million TRX. On-chain analytics firm Lookonchain put the total identified losses at around $356.86 million, slightly above Bitget's own $351.6 million figure.
How the Breach Happened
CEO Gracy Chen said private keys were not compromised; instead, attackers appear to have breached a core wallet backend, spoofed transaction data, and triggered Bitget's own authorization process to approve the transfers. Cold wallets were unaffected. After the funds left, attackers moved and swapped assets through decentralized protocols including UniswapX and 1inch. Bankless reports that Lookonchain has since tracked attackers swapping most of the stolen EVM assets into 67,982 ETH worth roughly $183 million, while the stolen XRP remains largely split across attacker wallets.
Bitget's Response and a Possible North Korea Link
Withdrawals remain suspended while deposits and trading continue, and Bitget says its $464M+ User Protection Fund will fully cover the loss with customer balances intact. Chen says some stolen funds have already been recovered. Investigators are examining a possible North Korean connection: Chen says identified IP addresses matched VPN choices associated with a DPRK group. Separately, Bitget's security team, working with Mandiant and SlowMist, strongly suspects the North Korean Lazarus Group may be behind the incident.
Sources: Bankless News, Research and Analysis, Coinpedia Fintech News
Trading involves risk.