
Hackers stole approximately $387.5 million in cryptocurrency from Bitget exchange on September 24 by exploiting a backend system to spoof transaction data, with North Korea's Lazarus Group suspected but unconfirmed; Bitget says its User Protection Fund will cover losses and customer balances remain intact.
AI-generated summary
Bitget is a major cryptocurrency exchange that established a User Protection Fund to cover potential hack losses, which grew from $300 million in 2023 to over $464 million. North Korea's Lazarus Group has been linked to multiple large crypto heists, including the $1.4 billion Bybit hack in February 2025.
Hackers stole roughly $387.5 million in crypto from Bitget yesterday in what is believed to be the biggest crypto hack of the year. The likely suspect is, as usual, North Korea—though that’s yet to be confirmed, and Bitget says law enforcement is now investigating.
Here’s what happened: Bitget's security systems detected unauthorized transfers moving out of some of its hot wallets at 18:31 UTC on September 24. Within about an hour, on-chain investigators had already tallied roughly $183 million in stablecoins, Ethereum, and other crypto assets sliding out of wallets tagged as belonging to the exchange.
By the time Bitget went public hours later to confirm the hack, total losses had grown to $351.6 million. The crypto exchange, one of the largest in the industry, updated that tally to $387.5 million today.
Bitget CEO Gracy Chen explained what happened in a livestream and a string of posts on X. "They did not forge user withdrawal requests, nor did they obtain our private keys of the cold wallet and any hot, warm wallet," she said. Instead, attackers broke into a backend system inside Bitget's wallet infrastructure and used it to spoof transaction data, tricking the exchange's own authorization process into approving payouts that looked routine.
In plainer terms, nobody stole the vault combination. Someone forged paperwork convincing enough that the system signed off on it without asking questions—the digital equivalent of slipping a fake withdrawal slip past a bank teller who checks the form, not the person.
Blockchain sleuths had pieces of the story before Bitget confirmed anything. Pseudonymous researcher DCF GOD flagged a freshly created wallet that spent $19.67 million in USDT0—a cross-chain version of the dollar-pegged stablecoin Tether—to buy 7,111 ETH in six minutes, paying roughly 5% above market price through decentralized exchanges UniswapX and 1inch Fusion.
More wallets tagged as Bitget's followed, sending assets across at least five blockchains to addresses the attacker controlled. The single biggest piece of the haul turned out to be roughly 103 million XRP, worth about $157 million.
Chen said the outflow has since been stopped and no further unauthorized transfers are possible. Bitget's User Protection Fund, which holds more than $464 million, will cover the full loss, she said, meaning customer account balances stay intact even though the money itself is gone.
Deposits and trading kept running throughout; withdrawals alone were frozen as a precaution.
Bitget built that protection fund years ago for exactly this potential scenario, given how common hacks unfortunately are in the industry. Back in 2023, the protection fund stood at $300 million, set aside specifically to cover hacks and theft so users wouldn't be left holding the loss.
North Korea is the usual suspect
As far as who was behind the hack, Chen has pointed a finger at Pyongyang, though carefully. "We've identified some IP addresses that match the VPN choices by a certain DPRK group," she said, adding that "the pattern looks very much like what the North Korean team did before."
She's also said the on-chain signatures line up with techniques tied to North Korean state-linked hacking groups, while stressing that the attacker's identity hasn't been confirmed and that no technical evidence has been made public.
Chen said she has personally been targeted by the same group before, losing about $80,000 from a personal wallet outside Bitget.
North Korea's Lazarus Group, also tracked under the codename TraderTraitor, has been blamed for the industry's biggest heists, including the Bybit lost $1.4 billion hack in February 2025, which the FBI confirmed weeks later was North Korean work. Blockchain analytics firm Chainalysis puts the country's 2025 haul at more than $2 billion.
AI outlook — possibilities, not facts
Law enforcement will trace some stolen funds through blockchain analysis
Likely · Within weeks
Bitget will implement additional backend security measures
Very likely · Within days

Magic Eden warned that NFTs listed on its EVM marketplace between February and October 2024 could be affected by an exploit in Payment Processor V2, urging users to revoke approvals on Ethereum, Polygon, and Base. While no live listings were impacted, an attacker stole various NFTs and 660 WETH, though a whitehat rescue recovered over 23,000 NFTs worth $5.7M. The company has since exited Ethereum and Bitcoin support to focus on Solana.

Security firm SlowMist reports no confirmed cryptocurrency thefts linked to a recent Safari exploit targeting iPhones. While the exploit can access Keychain data, the firm clarifies that the widely reported iOS 13-26.5 range is preliminary and unverified.

MultiversX brought its blockchain mainnet back online Thursday, Sept. 24, about five days after an exploit-related halt. While block production has resumed, crypto exchanges like Kraken maintain trading and funding restrictions.

A whitehat moved 3,832 NFTs from hundreds of wallets amid vulnerability concerns regarding NFT marketplace Magic Eden. Yuga Labs executives confirmed the rescue operation, while Magic Eden has not publicly confirmed an exploit.

Researchers at [[alloc] init] published a 56-page paper detailing Shielded Bitcoin, a protocol enabling private transfers on Bitcoin's base layer using zero-knowledge proofs and encrypted notes.

Payy has frozen its stablecoin payment network and card transactions after its Ethereum bridge contract was exploited and drained on Sept. 24.