A Breach That Stayed in One Tier

Bitget's security systems detected unauthorized transfers from a portion of its hot wallets at 18:31 UTC on September 24. The exchange says cold wallets and the vast majority of platform assets were never touched, and its separate self-custodial Bitget Wallet product was unaffected. The transfers moved ether, XRP, USDT, USDC, Avalanche and BNB across five networks.

Bitget put the loss at $351.6 million and suspended withdrawals as a precaution while its security team ran a full review. CEO Gracy Chen said customer account balances remain accurate and that deposits kept processing normally throughout, and promised a complete incident report within 24 hours.

The Safety Net Had a Floor, and This Hit It

Bitget's User Protection Fund exists for exactly this scenario, and it held roughly $464 million going into the breach. Covering the full $351.6 million loss from that fund alone would leave about $112.4 million behind, under the $300 million floor Bitget has stated it keeps the fund above. The exchange is not short of money. It is short of the specific buffer built for this exact kind of day.

Chen said the company holds more than $1 billion in proprietary assets and would replenish the fund, and that customer funds stay backed on a 1:1 basis regardless. The gap this breach opened is being closed by the company's balance sheet, not by users.

FigureAmount
Protection fund before the breach$464 million
Assets stolen (about 76 percent of the fund)$351.6 million
Fund left if the loss is paid in full$112.4 million
Bitget's stated minimum for the fund$300 million

Who Might Be Behind It, and Why That Is Still Unconfirmed

Chen said investigators found IP addresses tied to VPN services previously linked to North Korean hacking operations, and the attack pattern echoed earlier campaigns attributed to the same actors. A separate blockchain analyst traced some of the stolen XRP to July's AFX hack, which investigators had already linked to Lazarus Group. Bitget itself describes the North Korea link as a working theory, not a conclusion, and researchers say the attribution has not been independently confirmed.

That caution matters more than it might seem. State-linked groups target custodial crypto infrastructure specifically because the payoff is large and the forensic trail is hard to close quickly, which is also exactly why the defense has to assume a breach will eventually succeed rather than betting everything on keeping one out.

What Any Business Holding Customer Funds Should Take From It

The tiering did its job. Splitting assets across hot, warm and cold storage meant a breach of the internet-facing layer could not reach the bulk of platform funds, and that containment held even against an attacker good enough to be a suspected state actor. That part of the design is the template worth copying, for a crypto exchange or for any business that separates access tiers around its most valuable systems.

The part worth fixing is sizing. A reserve fund built to cover a breach still has to clear your own stated floor after paying out, not just cover the loss itself. Bitget's fund could absorb this one and still needed a $1 billion balance sheet standing behind it to avoid breaking its own rule. Size the buffer for a bad day plus your minimum, not for a bad day alone.