markets

Bitget Hack: Forged Transfers, Not Stolen Keys, Cost $352M

Summarized from Forexlive

Attackers manipulated Bitget's backend to authorize transfers without cracking private keys. CEO links breach to North Korea.

Bitget Hack: Forged Transfers, Not Stolen Keys, Cost $352M

A sophisticated cyberattack on crypto exchange Bitget drained roughly $352 million last Thursday — not by cracking the cryptographic locks that protect digital wallets, but by forging the documents that unlock them. Bitget's preliminary security findings indicate that attackers infiltrated a critical backend wallet system, manipulated transfer details, and then triggered the exchange's own legitimate signing process to push the funds out. Private key leakage, which would have posed a far broader threat to user wallets, has been ruled out.

Chief executive Gracy Chen drew a comparison to Bybit, which survived a $1.5 billion hack, to argue that Bitget has the reserves to absorb the blow. She pointed to a protection fund exceeding $465 million — enough to cover the loss on its own — and noted the exchange holds more than $1 billion in its own capital. Still, withdrawals remain frozen while trading continues, and the fund's true test will come when those withdrawal gates reopen.

Read more Human-Computer Interaction Market Projected to Hit $1.97T by 2030 →

The attack's mechanics recall a familiar form of corporate fraud: invoice manipulation. The thieves did not steal the boss's signature; they entered the payments system, rewrote the payee details, and let the company's own approval chain do the rest. That framing is analytically important because it shifts scrutiny from cryptographic infrastructure to internal controls and backend access management — a vulnerability category that even technically sophisticated exchanges have repeatedly underestimated.

On-chain tracker Lookonchain put a finer point on what was taken. XRP dominates the haul at approximately $157.5 million, making it the single largest portion and one that had attracted little public attention before Thursday. About $85.8 million in ether followed, alongside stablecoins including USDT, USDC and USDT0, plus smaller positions in Tether Gold, BNB, AVAX and TRX. The attacker still controls substantial amounts of both XRP and ETH, a dynamic that could generate selling pressure if those holdings are liquidated rather than routed through privacy tools over time.

Chen said the attack bears the hallmarks of North Korean state-linked hackers, citing IP address patterns consistent with a DPRK-associated group — though she emphasized the attribution is not yet confirmed. North Korean cyber units have been linked to several of the largest crypto heists in recent years, reflecting a broader pattern of state-sponsored financial crime targeting digital asset infrastructure. Continue reading at Forexlive.

Frequently Asked Questions

Q.How did hackers steal funds from Bitget without taking private keys?

Attackers breached Bitget's critical backend wallet system, forged transfer details inside it, and then triggered the exchange's own authorized signing process to approve and send the funds — similar to corporate invoice fraud where the payment system itself is manipulated rather than the credentials stolen.

Q.Which cryptocurrencies were stolen in the Bitget hack?

The stolen assets included approximately 102.9 million XRP worth $157.5 million, 31,890 ETH worth $85.8 million, plus stablecoins such as USDT, USDC and USDT0, along with smaller amounts of Tether Gold, BNB, AVAX and TRX, totaling roughly $352–357 million.

Q.Can Bitget cover the losses from the hack?

CEO Gracy Chen says Bitget's protection fund, which exceeds $465 million, is sufficient to cover the stolen amount on its own, and the exchange holds over $1 billion in its own capital. She cited Bybit's recovery from a $1.5 billion hack as a comparable precedent.

More in markets →