The cryptocurrency exchange Bitget has suffered a major security attack, with the platform stating that losses have exceeded 387 million US dollars. Following the incident, Bitget suspended withdrawals and began to investigate the backend system. Based on the amounts disclosed so far, this is one of the largest crypto attacks of the year.
The attack path points to the backend approval system.
Bitget The Chief Executive Officer Gracy Chen stated during a live broadcast on the X platform that the platform suspects that the attackers exploited the backend system used to process wallet transactions, allowing abnormal withdrawals to be identified as normal operations within the internal processes. She mentioned that the attackers did not directly steal the private keys but instead induced the internal approval process to approve the relevant transfers.
Bitget indicates that affected are the hot wallets and warm wallets controlled by the platform. These types of wallets are typically used for processing user transactions and withdrawals. Bitget Wallet, as an independent self-managed product, is not affected, and users retain full control over their assets.
Withdrawal suspended; the platform has initiated tracking and a reward program.
According to Bitget, the relevant vulnerabilities have been fixed, and the platform is still continuing to review its security systems. As more abnormal transactions are identified, the estimated losses have also been raised. The newly discovered suspicious transfers involve multiple networks, including the privacy-conscious Zcash and the commonly used TRON for stablecoin transfers.
After the incident, Bitget collaborated with a third-party security firm, Mandiant, and Mànwù to conduct an investigation. A real-time tracking panel was also launched to help external researchers and other platforms identify the attacker's address. The platform also introduced a reward program for the recovery of funds, offering a maximum reward of 5% for any successfully frozen or recovered amounts.
- Current loss estimate: over $387 million
- Protection Fund Size: Over $464 Million
- Maximum reward ratio: 5% of the recovered or frozen funds
Bitget indicates that the platform's user protection fund can be used to compensate for losses caused by security incidents. Based on the current scale, even if the stolen funds cannot be recovered in the end, the reserve amount is sufficient to cover the current losses.
North Korean hacking risks are heating up again
Bitget suspects that this attack is directed at North Korean hackers. Blockchain analysis firm Chainalysis previously stated that in 2025, hackers associated with North Korea stole approximately $2 billion in encrypted assets, setting a record. It is widely believed that such attacks are related to the country's efforts to obtain foreign exchange under sanctions.
Chainalysis also mentioned that in recent years, relevant hacker groups have more frequently targeted exchanges and large cryptocurrency companies. Common tactics include impersonating recruiters to steal credentials, making false investment offers to executives, and even inserting IT personnel into the internal structures of these companies.
This incident is also the latest in a series of security breaches in the cryptocurrency industry over the past three months. Earlier this month, a layer-2 network Liquid Network designed for Bitcoin transactions suffered an attack worth approximately $319 million; at the end of July, a hardware wallet Coldcard experienced a theft of about $116 million in Bitcoin. These consecutive attacks once again highlight that trading platforms and custody services remain some of the most vulnerable aspects of the industry.












