Bitget has frozen withdrawals after intruders moved $351.6 million out of its hot and warm wallets, an attack the exchange blames on North Korean operators.
The exchange said its security systems flagged unauthorized transfers at 18:31 UTC on September 24. Cold storage and the overwhelming majority of platform assets stayed untouched, and customer balances remain accurate, it said. Deposits and trading continue, while withdrawals are paused for a review being run by Mandiant and SlowMist.
According to CEO Gracy Chen, the stolen assets span ETH, XRP, BNB, AVAX, USDT and USDC. The affected chains include Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base. Some of those foundations have already frozen wallets tied to the attacker.
Chen’s account of the method is direct. An intruder reached a critical backend system inside the wallet infrastructure, then forged transaction data and rode the exchange’s own authorization process to move funds out. She said the route is now shut and that investigators are still working out how the system was breached.
The trail points to a familiar suspect. Chen said IP behavior and on-chain analysis closely match known North Korean tradecraft. A week earlier, SentinelOne tied the TraderTraitor group, the crew behind the $1.5 billion Bybit theft and the $292 million KelpDAO bridge raid, to an intrusion at an India-based IT services firm.
Bitget Wallet, a self-custodial product, runs on separate infrastructure and was unaffected.
