Cryptocurrency exchange Bitget has suffered a severe cybersecurity breach, with malicious actors compromising several hot wallets and draining an estimated 351 million dollars in digital assets. The incident triggered immediate operational disruption across the platform, prompting emergency containment procedures while onchain analytics systems flagged massive, anomalous movements of capital leaving the exchange infrastructure.
Onchain Monitors Detect Initial Fund Movements
The security compromise was first detected by automated onchain tracking mechanisms that monitor large-scale cryptocurrency movements across networks. Initial tracking alerts indicated that more than 180 million dollars in digital tokens were transferred from known Bitget depository hot wallets to completely unidentified recipient addresses. The breach continued to widen as attackers drained additional pools, ultimately lifting the estimated total value of the stolen assets to roughly 351 million dollars before the vulnerability could be fully contained.
Stolen Assets Dumped Below Market Prices
The exploit spanned multiple high-liquidity digital currencies and stablecoins. Among the compromised tokens were Ether (ETH), USD Coin (USDC), Tether (USDT), BNB, and Avalanche (AVAX). Blockchain transaction records reveal that the perpetrators acted swiftly to liquidate and obfuscate the proceeds. Rather than seeking optimal market execution, the attackers dumped the stolen tokens at valuations significantly below prevailing spot market rates. Furthermore, they made heavy use of cross-chain bridging protocols, funneling the converted assets across multiple decentralized networks in a calculated attempt to break tracking trails and impede asset freezes.
Withdrawal Freezes and Platform Disruptions
As the unauthorized draining of hot wallets unfolded, regular exchange customers encountered operational roadblocks. Multiple traders reported that withdrawal requests were failing to process through the user interface, leading to mounting anxiety across community forums. In response to the breach, Bitget officially halted all outgoing withdrawals across the platform. Company representatives confirmed that withdrawal channels will remain suspended while internal technical teams complete exhaustive security audits and verify the integrity of all surviving wallet systems.
Protection Reserve Exceeds Exploited Value
Seeking to calm investor panic, Bitget management insisted that user balances will not bear the financial brunt of the hack. The company underscored that the entire stolen amount falls well within the coverage limits of its dedicated User Protection Fund. This specialized reserve holds over 464 million dollars in assets, providing a substantial capital buffer beyond the 351 million dollar breach. Providing assurances on the matter, Grace stated, "Every dollar and every decision will be accounted for, transparently and in full." Company leadership reiterated that customer holdings remain secure and that full transparency will guide every compensatory step.
Digital Traces Point Toward DPRK Cyber Actors
Preliminary forensic investigations into the attack vectors and communication nodes have pointed toward state-sponsored cyber operations. According to Grace, network internet protocol addresses associated with the intrusion show strong links to the DPRK hacking collective. Threat groups affiliated with North Korea have a documented history of targeting digital asset exchanges worldwide to bypass international economic restrictions. Bitget stated that comprehensive security reviews are ongoing to remediate all vulnerabilities before customer withdrawal functions are restored.



















