Bitget Hack

Reported loss $352M
ethereum tron xrp zcash
Access Control

What happened

On September 24, 2026, centralized exchange Bitget suffered a major infrastructure breach resulting in ~$351.6 million stolen from its hot and warm wallet layers. Bitget paused withdrawals while confirming its cold wallets remained secure and stating that its $464M+ User Protection Fund will fully reimburse user losses.

The attacker penetrated Bitget's core wallet backend infrastructure and spoofed internal transaction data to trigger authorized withdrawals across multiple blockchains without compromising private keys. Stolen assets included ETH, XRP, USDT, USDC, AVAX, and BNB. On EVM chains, the attacker converted most of the stolen proceeds into 67,982 ETH (~$183 million).

On-chain analysis and VPN traffic patterns linked the attack to North Korea's Lazarus Group (specifically the TraderTraitor subgroup) through bridged funds connected to the earlier AFX Trade exploit. Bitget contained the breach, stopped further unauthorized transfers, and is preparing system recovery before resuming withdrawals.

Protocol details

Classification CeFi / Key Compromise
Protocol Type Exploit/Access control
Protocol links Website @bitget

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.