Breaches · 1h ago
Bitget disclosed a $351.6 million theft from its hot and warm wallets, and said suspected North Korean-linked hackers were behind the loss. The exchange said tracing is underway.
The key issue is custody: hot and warm wallets stay online so an exchange can move funds quickly, but if attackers gain signing control they can approve transfers that look legitimate and move assets out immediately. That makes the incident about user funds, not just Bitget’s internal systems.
For anyone holding assets through an exchange or other third-party custodian, the exposure sits with the wallet model itself. If the online signing layer is compromised, cleanup depends on tracing and coordination after the fact, not on wiping a server and calling it done.
2 sources covering this story
Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
Bitget says suspected North Korean actors stole $351.6 million after compromising a backend wallet system and spoofing transaction data.
Hackers steal $351.6 million in Bitget crypto exchange hack
Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets.
Part of the PlainSec briefing for 2026-09-25