Cryptocurrency exchange Bitget has paused customer withdrawals after a hack led to the theft of an estimated $387.5 million in various digital assets. The incident, which began with unauthorized transfers detected on September 24, involved compromising a critical backend wallet system that spoofed transaction data to trigger the exchange's authorization process. While the company stated that private keys were not compromised, the breach affected hot and warm wallets, though cold wallets remained secure. Initial estimates of the loss were around $351.6 million, but a more complete accounting, including affected assets on Zcash and TRON, raised the figure to $387.5 million.

Bitget CEO Gracy Chen indicated that preliminary evidence, including IP behavior patterns and on-chain analysis, strongly suggests the involvement of North Korean hacking groups. The attack method mirrored previous operations attributed to the country. Affected assets included XRP, ETH, USDT, ZEC, USDC, XAUt, BNB, AVAX, and TRX, spread across multiple blockchain networks. XRP reportedly accounted for the largest loss on a single chain. Deposits and trading continue normally, but withdrawals are suspended for a security review, with a plan for their restoration expected by September 26th, 4:00 AM UTC.

Bitget has assured users that all customer funds are safe, as the loss is fully covered by its User Protection Fund, which holds over $464 million. The company has engaged independent cybersecurity experts Mandiant and SlowMist to assist with the investigation and recovery efforts. Some affected assets have already been frozen through collaboration with industry partners, and Bitget has launched a Recovery Bounty Program, offering 5% of successfully frozen or recovered funds to those who contribute to these efforts.