# Bitget Hacked for $351.6M *Author: David Feld* *Published: Sep 25, 2026* *Source: https://www.bankless.com/read/news/bitget-hacked-for-351-6m* --- Crypto exchange Bitget was hacked for $351.6M Thursday, with attackers now consolidating much of the haul into assets harder to freeze. ## What's the Scoop? - **$351.6M stolen:** Bitget [confirmed the breach](https://www.bitget.com/support/articles/12560603896024) after detecting unauthorized transfers from portions of its hot wallets Thursday evening. Cold wallets were unaffected. CEO Gracy Chen later said [private keys were not compromised](https://en.bloomingbit.io/feed/news/121028); instead, attackers appear to have breached a core wallet backend, spoofed transaction data, and triggered Bitget's own authorization process to approve the transfers. Exactly how they entered the backend remains unknown. - **Getting into unfreezable assets:** Since then, the attackers have rapidly consolidated stolen assets into native crypto that is much harder to seize. Lookonchain says they have [swapped most of the stolen EVM assets into 67,982 ETH](https://www.lookonchain.com/feeds/74089), worth roughly $183M, while roughly 103M XRP was also stolen and remains largely split across attacker wallets. - **Bitget responds:** Bitget has flagged attacker addresses, brought in law enforcement and onchain security firms, and Chen says [some stolen funds have already been recovered](https://cointelegraph.com/news/bitget-ceo-suspects-north-korea-behind-352m-hack-citing-ip-clues). Withdrawals remain suspended, though deposits and trading continue, while Bitget says its $464M+ User Protection Fund will fully cover the loss and customer balances remain intact. As you might expect, investigators are examining a possible North Korean connection: Chen says identified IP addresses matched VPN choices associated with a DPRK group, while onchain researcher Specter independently [linked part of the stolen XRP trail](https://cointelegraph.com/news/bitget-ceo-suspects-north-korea-behind-352m-hack-citing-ip-clues) to infrastructure connected with the earlier AFX exploit, which AFX attributed to North Korea-linked TraderTraitor. > [ — (@) > ](https://twitter.com/GracyBitget/status/2103235655879074084) --- *This article is brought to you by [NEAR](https://www.bankless.com/sponsor/near-1785257427?ref=read/news/bitget-hacked-for-351-6m)*