Bitget reports $387.5 million crypto theft, blames North Korean hackers

Cryptocurrency exchange Bitget disclosed a security breach in which about $387.5 million in digital assets were stolen. Attackers compromised a backend wallet system and manipulated transfer data to trick automated authorization, according to the company. Bitget’s CEO said initial evidence points to North Korean hacking groups, while the exchange said its user protection fund will cover losses and cold wallets were not affected.
Bitget said intruders reached a backend part of its wallet system and altered transfer records so automated checks approved unauthorized withdrawals. Assets were routed across several blockchains to attacker-controlled addresses. The exchange initially cited $351.6 million, later raising the figure to $387.5 million after tracing more assets on Zcash and TRON; it described this as fuller accounting, not a second breach.
CEO Gracie Chen linked initial evidence to North Korean hacking groups, citing IP, VPN, and behavioral patterns. Bitget said its user-protection fund, above $464 million, will cover losses, so customer balances should not suffer. Cold wallets and the separate self-custody Bitget Wallet were untouched; parts of hot and warm wallet layers were affected.
The breach could deepen unease among crypto users, especially those who assume exchange safeguards are sufficient. If the protection fund covers losses as stated, direct customer harm may be limited, but confidence in centralized platforms could still weaken. Exchanges may face pressure to strengthen backend controls and authorization checks, while investigators and blockchain analysts could see more