---
title: "Bitget Links $351.6M Wallet Breach to North Korean Hackers"
description: "Bitget reported that a $351.6 million wallet exploit bears the hallmarks of North Korean cybercriminals, putting about 76% of its $464 million user protection fund at risk while withdrawals remain paused."
author: "CryptoResearch AI"
published: "2026-09-25T10:54:28.250Z"
updated: "2026-09-25T10:54:28.251Z"
category: "security"
reading_time_minutes: 2
content_type: "editorial"
canonical: "https://cryptoresearch.news/news/bitget-links-351-6m-wallet-breach-to-north-korean-hackers"
tags: ["Bitget", "Hacks", "North Korea", "Lazarus Group", "XRP", "Security"]
---

# Bitget Links $351.6M Wallet Breach to North Korean Hackers

> Editorial content, written by CryptoResearch.

Bitget reported that a $351.6 million wallet exploit bears the hallmarks of North Korean cybercriminals, putting about 76% of its $464 million user protection fund at risk while withdrawals remain paused.

Bitget said its $351.6 million wallet exploit from Sept. 24 displays hallmarks pointing to North Korean cybercriminals. The exchange reported that IP logs and on-chain movements aligned with patterns typically favored by North Korean hacking units.

External security firms Mandiant and SlowMist have been brought in to probe the intrusion alongside law enforcement, according to Chief Executive Officer Gracy Chen. Independent on-chain analyst Specter separately connected the stolen XRP to a $24 million exploit targeting AFX in July, which had been attributed to the TraderTraitor cluster linked with Lazarus Group. Bitget noted that external investigators have not yet independently confirmed the North Korean link.

The exploit drained funds including ETH, XRP, BNB, AVAX, USDT, and USDC across several networks, including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain, and Base. Chen pointed out that XRP suffered the steepest losses on any individual blockchain. Bitget stated that its cold storage remained completely secure, while its self-custodial Bitget Wallet product was not impacted.

Multiple blockchain foundations have already frozen addresses connected to the attacker, which could lower the final damage from the initial $351.6 million figure. Whatever shortfall remains will be absorbed by Bitget's User Protection Fund, an emergency backstop holding 5,500 Bitcoin worth upwards of $464 million.

Covering the entire $351.6 million balance would consume around 76% of that protection reserve, though the final hit could change based on recovered assets and Bitcoin price fluctuations. Chen confirmed that Bitget plans to replenish the fund after absorbing the losses, pointing to more than $1 billion in company-owned assets and noting that customer deposits remain fully backed 1:1.

Bitget's pre-attack proof-of-reserves report from Sept. 17 showed a 135% aggregate reserve ratio across 19 assets, though it does not reflect the current post-exploit balance sheet. Client withdrawals will stay suspended until safety reviews are complete, with Chen stating the exchange will only set a reopening date once it has full confidence in its systems.

## Sources

- [Crypto slate](https://cryptoslate.com/bitgets-north-korea-linked-352-million-hack-could-drain-76-of-its-protection-fund/)

---

Published by CryptoResearch. Canonical version: https://cryptoresearch.news/news/bitget-links-351-6m-wallet-breach-to-north-korean-hackers
