LiMP VPN
← All news

Bitget Hack: Hackers Steal $351.6M From Crypto Exchange

Bitget Hack: Hackers Steal $351.6M From Crypto Exchange

In short: On September 24, 2026, crypto exchange Bitget disclosed a $351.6 million theft after attackers compromised an internal backend server and spoofed transaction data, tricking the withdrawal authorization pipeline into approving fraudulent transfers from hot and warm wallets. Cold storage was untouched, and the exchange paused withdrawals. Bitget CEO Gracy Chen said the attack bears the hallmarks of North Korean hacking groups — investigators reportedly found IP addresses tied to VPN services previously used by such groups. Here's what happened and how everyday users can protect their accounts and crypto holdings.

What happened

The incident was first flagged at 18:31 UTC on September 24, 2026, when unauthorized transfers began draining portions of Bitget's wallets. The exchange runs a three-tier wallet architecture — cold, warm, and hot — and only the warm and hot layers were affected; cold wallets remained secure. For more on protecting your traffic and digital accounts, see the LiMP VPN security blog.

Bitget confirmed the $351.6 million loss and temporarily suspended withdrawals during the investigation. The company says its User Protection Fund holds over $464 million and pledged to make affected users whole from its own reserves.

How attackers got in: spoofed data, not stolen keys

According to reporting by CoinDesk, this wasn't a classic private-key theft. Attackers compromised an internal wallet-management service and pushed fabricated recipient addresses, amounts, and metadata through the same authorization pipeline used for everyday customer withdrawals. The system processed the forged requests as legitimate — from the infrastructure's point of view, it looked like a routine withdrawal, even though every detail was fake.

This vector is arguably more dangerous than classic key theft: it doesn't require compromising cold wallets or seed phrases — just one internal service the exchange treats as trusted.

Who is behind the attack

Bitget CEO Gracy Chen said the incident likely traces back to North Korean state-linked hacking groups. Her team reportedly found IP addresses in the attack logs previously associated with VPN services used by North Korean actors in earlier operations — an attempt to mask the true origin of the traffic through intermediary networks. This is a common but not conclusive attribution signal: disguising or rerouting a real address makes attribution harder, but on its own it isn't proof and doesn't replace a full technical audit.

September 2026 has been the worst month of the year for crypto theft overall: according to CryptoSlate, total losses across the industry topped $684 million, including another major incident on the Liquid Network earlier in the month.

Why this matters beyond crypto holders

The Bitget case illustrates a broader pattern in modern attacks: adversaries increasingly target weak points in internal backend processes — places where an authorization system trusts data that merely looks legitimate — rather than hunting for cryptographic flaws. The same principle applies to banking apps, enterprise CRMs, and any service where a fund transfer or data change depends on an internal API. The takeaway for ordinary users: even a large platform with a three-tier custody architecture can have a single internal service compromised, and neither company size nor reputation is a guarantee against it.

How to protect your accounts and assets

  • Keep core holdings in cold storage. A hardware wallet or offline storage is immune to a compromised exchange backend — an attacker cannot forge a transaction without your physical device.
  • Enable two-factor authentication and login/withdrawal alerts. Real-time notifications let you catch a suspicious withdrawal within minutes, not days.
  • Don't keep more on an exchange than you can afford to have frozen during an investigation. Even with a compensation fund, withdrawals can stay locked for weeks.
  • Encrypt your connection on every device. Traffic encryption via LiMP VPN won't stop a backend breach at the exchange — that's the platform's responsibility — but it protects your logins, sessions, and communications from interception on public or untrusted networks while you manage your accounts. A legitimate no-logs VPN is a protection tool for you, not a way to hide someone else's attack: bad actors use intermediary networks to cover their tracks, not for user privacy.

See LiMP VPN plans — traffic protection on every device starting at $0.99 per month.

Sources