Bitget Lost $352 Million in a Backend Spoofing Attack — and North Korea May Be Behind It
Bitget CEO Gracy Chen said attackers compromised wallet infrastructure and faked transaction data, draining $351.6M without stealing private keys.
3 min read
Crypto exchange Bitget disclosed one of the largest hacks of 2026 on September 24: $351.6 million drained from hot and warm wallets after attackers compromised backend infrastructure — without stealing private keys or breaching cold storage.
CEO Gracy Chen said the attacker "compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out." Withdrawals remain suspended while a security review continues. Deposits and trading stayed open, and Bitget said its $464 million User Protection Fund would cover the loss.
A new attack pattern
Exchange hacks usually follow familiar scripts: stolen private keys, forged withdrawal requests, or social engineering of employees. Bitget's incident fits a less common but more alarming category — backend transaction spoofing.
In this model, attackers do not need keys at all. They compromise the systems that tell the exchange what to sign. If authorization logic trusts backend data more than independent verification, the exchange effectively signs attacker-crafted movements while believing they are legitimate internal transfers.
Chen explicitly ruled out private key compromise and said cold wallets were never at risk. Hot wallets — internet-connected liquidity buffers — and warm wallets — intermediate layers between hot and cold storage — bore the damage.
Attribution and recovery
During a live Q&A on X, Chen said preliminary investigation linked IP addresses to VPN services associated with North Korean hacking groups. North Korean actors were tied to an estimated $2.02 billion in crypto theft in 2025, including the FBI-attributed $1.5 billion Bybit hack.
Chen also said some stolen funds had been recovered through coordination with blockchain foundations and partners, without specifying amounts.
What this means for crypto infrastructure
The Bitget breach is a reminder that operational security is not just key management. Exchanges must treat wallet backends, transaction pipelines, and authorization workflows as tier-one attack surfaces — with separation of duties, independent reconciliation, and anomaly detection that does not depend on the same systems that initiate transfers.
For users, the incident reinforces cold-storage discipline for holdings you do not actively trade, and skepticism toward any mental model that equates "keys weren't stolen" with "we're safe."
For the industry, it adds pressure on proof-of-reserves, insurance funds, and real-time transparency during incidents. Bitget's protection fund covered users this time. Not every exchange maintains that buffer.
The macro picture
The hack landed on the same day Block announced Bitcoin Lightning integration into the x402 agent payment standard — a bet that crypto rails will power machine commerce. Incidents like Bitget simultaneously remind the market that those rails remain high-value targets for sophisticated nation-state actors.
Security and adoption are not opposing forces, but they move on different clocks. Until backend spoofing becomes harder and more expensive than it is today, exchange infrastructure will remain the soft underbelly of the crypto economy — even when keys stay in vaults.
More in cryptocurrency
Cubed
Write about the technologies shaping the future.
For developers, founders, and curious minds exploring AI, crypto, Web3, and emerging tech—signal over noise.
One free account across In Plain English, Stackademic, Venture, and Cubed.
How it works- AI, crypto & Web3
- Software & emerging technologies
- Analysis & practical resources
- Thoughtful voices, not hype
Sign in
Google or GitHub
Complete profile
Takes a few minutes
Get approved & publish
Start sharing
Why write for Cubed?
The future deserves thoughtful voices, not just louder headlines.




Comments
Loading comments…