Bitget said suspected North Korean hackers took $351.6 million from its hot and warm wallets after compromising a backend wallet system and triggering its authorization process to move funds out. The exchange said withdrawals are suspended, customer balances remain accurate, and Mandiant and SlowMist are helping with the investigation.
The attack did not depend on customer passwords or private keys. Bitget said the intruders spoofed transaction data inside its internal wallet path, so the platform itself approved transfers that looked legitimate. Some affected chain foundations have frozen attacker addresses, which can slow laundering and may help recovery, but it does not undo the original trust failure in the signing path.
For custodial exchanges and wallet providers, the exposure sits in the internal approval chain, not just at the login screen. If that path is reused across hot-wallet operations, a platform can be forced to move assets even while user-facing account data still looks normal.