Bitget lost $351.6M - and the private keys weren't compromised
September 24, 18:31 UTC: unauthorized transfers out of Bitget. Private keys intact. Attackers hit the critical backend of the wallet infrastructure and routed malicious transactions through it. $351.6M gone.
Per Lookonchain, the breakdown by stolen asset:
⏺️ 102.93M XRP - ~$157.5M (the single largest position)
⏺️ 31,890 ETH - ~$86M
⏺️ USDT, USDC, BNB, AVAX - the remainder
Cold wallets and the decentralized Bitget Wallet were untouched. Withdrawals are suspended; trading and deposits continue. The User Protection Fund stands at $464M - it covers the declared loss.
🟢 Mandiant and SlowMist are running the investigation. Bitget CEO Gracie Chen went live on X with preliminary findings:
"We found IP addresses matching the VPN choice of a certain North Korean group; the pattern is very similar to what the North Korean team has done before."
On-chain researcher Specter linked the stolen XRP to the "AFX EXPLOITER" cluster, which has previously been attributed to TraderTraitor. The connection to Lazarus remains unconfirmed. The FBI formally attributed the $1.5B Bybit hack to North Korean actors in early 2025. Bybit CEO Ben Zhou has already updated LazarusBounty, his cross-chain tracking service built to surface and freeze stolen assets. North Korean involvement remains a working hypothesis - not an official verdict.
🟢 The structural irony: XRP accounts for nearly half the haul - and it cannot be frozen. Ripple has no kill-switch for individual addresses in the XRP Ledger. USDT and USDC issuers have already started locking attack-linked addresses. The largest single piece of the theft stays liquid.
Neither Bybit in February 2025 ($1.5B) nor Bitget today broke cryptography. Both attacks targeted the operational layer around custody - there, a signing-interface compromise; here, a backend authorization breach. Different exchange, same playbook. $464M in the protection fund covers the loss on paper, but the structural question remains: why were $351.6M within reach of one compromised backend system?
➡️Crouton.digital | About us⬅️
