Bitget said suspected North Korean hackers stole $351.6 million from its hot and warm wallets, a fresh reminder that even large crypto exchanges remain exposed to fast-moving, state-linked thefts that can hit liquidity, trust and trading flows in one stroke.
Bitget Says Hackers Stole $351.6 Million

The breach matters economically because it lands squarely on the plumbing of the crypto market: exchange custody, withdrawal confidence and the ability of users to move capital in and out without interruption. Bitget said customer balances remain accurate and that its User Protection Fund, which it says holds more than $464 million, will cover the losses, but the incident still forced a temporary suspension of withdrawals while investigators and cybersecurity firms reviewed the damage.
Bitget said the attack was detected Thursday evening after its security systems flagged unauthorized transfers from a limited number of wallets. Chief executive Gracy Chen said the incident touched assets across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base, with ETH and XRP among the tokens affected. She said on-chain analysis and IP behavior were consistent with known North Korean hacker patterns and that some wallet addresses had already been frozen.
That attribution matters beyond this exchange. North Korean-linked groups have become one of the most disruptive actors in crypto theft, with the sector repeatedly absorbing losses that are not just criminal but geopolitical, helping finance sanctioned programs while imposing real costs on private markets. Chainalysis and Elliptic have both estimated the scale of those thefts in the billions, and the pattern has made crypto exchanges a persistent risk point for investors, regulators and insurers.
For markets, the immediate question is whether the breach dents confidence in centralized exchanges more broadly. Investors tend to price these events through the lens of operational risk and reputational damage rather than the direct loss alone. A major exchange can say it is solvent and still see activity, spreads and customer retention come under pressure if users begin shifting assets to self-custody or rival venues. That is especially relevant for listed crypto-linked names such as Coinbase, where sector-wide security scares can affect trading volumes and sentiment even when the company is not directly involved.
There is also a wider balance-sheet implication. Bitget said its cold wallets and most platform assets were secure, but the attack on backend wallet infrastructure underscores how exchanges can be vulnerable even without a full hot-wallet drain. The company has not yet explained how attackers spoofed transaction data and triggered authorization, a detail that will be closely watched because it speaks to whether the weakness was technical, procedural or human.
The case could also feed into the broader debate over whether exchanges need to hold larger protection pools, tighten approvals and expand real-time monitoring as the cost of doing business in a more hostile environment. In the near term, the market will watch for how quickly Bitget restores withdrawals, whether any additional wallets are flagged, and whether the incident prompts a wider selloff in exchange-related tokens or a renewed shift toward custodianship outside trading venues.
| Entity | Gains | Losses |
|---|---|---|
| Bitget User Protection Fund | ▲absorbs losses | ▼sees reserve hit |
| North Korean-linked hackers | ▲stolen crypto proceeds | ▼exposure to sanctions scrutiny |
| Bitget customers | ▲balances protected, funds covered | ▼temporary withdrawal freeze |
| Crypto exchanges | ▲push for tighter security | ▼trust and volume pressure |
