Coindoo first covered the unusual wallet movements in its earlier report, when funds from Bitget-linked wallets were moving to a […]
The post Bitget Breach: North Korea Link Probed, Withdrawals Paused appeared first on Coindoo.
Coindoo first covered the unusual wallet movements in its earlier report, when funds from Bitget-linked wallets were moving to a fresh address and being swapped on-chain. Bitget has since confirmed that the transfers were unauthorised.
How the Bitget Story Changed Overnight
| Stage | What was known |
|---|---|
| Initial on-chain alert | More than $170 million was seen moving from Bitget-linked wallets to a fresh address, where assets were reportedly swapped. |
| Bitget’s confirmation | The exchange said unauthorised transfers affected approximately $351.6 million and suspended withdrawals. |
| Technical update | Bitget says an attacker compromised a backend wallet system and triggered its authorisation flow with spoofed transfer data. |
| Latest attribution clue | Its CEO reportedly says North Korean involvement cannot be ruled out, but no group has been named. |
The two dollar figures should not be read as competing estimates of the same thing. The $170 million number came from the initial visible on-chain flow. Bitget’s later $351.6 million figure is its internal estimate of the assets affected by the breach.
Bitget has not published a wallet-by-wallet reconciliation explaining the difference. What is clear is that the first alert captured only part of a wider incident that the exchange later confirmed from inside its own systems.
The North Korea Clue Is Not a Final Attribution
During a live security update, Bitget CEO Gracy Chen said some IP addresses associated with the attack matched VPN-use patterns linked to a North Korean hacker organisation. She also said the activity resembled previous attacks associated with North Korean operators, according to ChainCatcher’s report.
That is a preliminary lead, not a completed attribution. Bitget has not named a group or released the forensic evidence behind the assessment. The company’s current position is that North Korean involvement cannot be ruled out while investigators continue to trace the intrusion.
The Attack Did Not Require a Stolen Private Key
Bitget’s explanation changes the technical question around the breach.
In a September 25 update, Chen said the attacker compromised a critical backend system within the exchange’s wallet infrastructure. Bitget says the system was then used to create spoofed transfer data that reached its authorisation process and moved funds out.
Here is what we can confirm at this stage:
On the attack:
Our security team has made initial progress in tracing the source. The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization… https://t.co/5nINjwbXpC— Gracy Chen @Bitget (@GracyBitget) September 25, 2026
The exchange says a private-key leak has been ruled out. It also says it has contained the incident and that no further unauthorised transfers are possible.
That does not make the breach less serious. It shifts the focus from key custody to the systems around it. If Bitget’s account is confirmed, the attacker did not need to possess a wallet key; it needed access to infrastructure capable of producing transfer information that the approval process accepted.
The full incident report therefore matters more than the early North Korea clue. It needs to explain how manipulated data entered the authorisation flow, what controls failed to stop it and what has changed before withdrawals resume.
A Protection Fund Can Cover Losses, Not Restore Access
Bitget says its cold wallets were not affected and that the $351.6 million loss falls within the coverage of its User Protection Fund, which it says holds more than $464 million. The exchange also says customer account balances remain accurate.
| What Bitget says is covered | What users still need answered |
|---|---|
| The estimated $351.6 million loss | When withdrawals will restart |
| Customer account balances | Whether every affected system has been repaired |
| Cold-wallet assets | A full technical explanation of the breach |
This is the practical distinction for users. The protection fund addresses whether Bitget says it can absorb the financial loss. It does not, by itself, restore confidence that the wallet systems are ready for normal withdrawals.
Deposits and trading remain available, according to Bitget’s official security notice. Withdrawals remain suspended while the exchange works on remediation and security hardening. Chen said Bitget would announce a restart schedule only once it can give a confirmed timeframe.
The Remaining Question Is Inside Bitget’s Systems
The initial $170 million alert asked whether the suspicious wallet movements were real. Bitget has now answered that part: it says the transfers were unauthorised and the total exposure was far higher.
The harder question remains. If private keys were not stolen, how did a compromised backend system generate transfer data that Bitget’s authorisation process accepted?
That answer—not another revised loss estimate—will show whether the exchange has addressed the weakness that allowed the breach in the first place.
This article is provided for informational purposes only and does not constitute financial or investment advice. Attribution and technical findings can change as Bitget and independent investigators release further evidence.
The post Bitget Breach: North Korea Link Probed, Withdrawals Paused appeared first on Coindoo.
Source: https://coindoo.com/bitget-breach-north-korea-link-probed-withdrawals-paused/
More Crypto News
Check our Market Overview
Disclaimer: This article is for informational purposes only and does not constitute financial advice. Always conduct your own research (DYOR).




