Bitget lost $351.6 million in unauthorised transfers from its hot and warm wallets on Thursday, the exchange has confirmed. Chief executive Gracy Chen said attackers compromised a backend system inside the company’s wallet infrastructure, used it to spoof transaction data, and then pushed 19 transfers through Bitget’s own authorisation process. Cold storage was not affected.
Chen was emphatic that no private keys were compromised, and likened the attack to forging withdrawal slips rather than breaking into the vault. She told reporters that investigators had traced IP addresses to VPN services previously used by a North Korean hacking group, CNBC reported, although some analysts caution that the Lazarus label covers a loose collection of operations and that any attribution this early is preliminary.
Bitget says its User Protection Fund, which holds more than $464 million, will absorb the full loss and that account balances are accurate. Deposits and trading remain open, while withdrawals are frozen pending a security review. The distinction Chen is drawing matters beyond one exchange. The industry has spent years hardening key storage with multi-party signing and hardware modules, and an attack that feeds forged instructions into an approval system walks past all of it, because the system signs what it is told to sign.
What has not been published is a timeline for withdrawals or a technical account of how one backend system could hand the signing process false data unchallenged. Early estimates of the loss circulated at around half the final figure before Bitget confirmed it, and the number is still the company’s own. A fund that covers the hole is reassuring. A frozen withdrawal button is what customers will judge Bitget on.



