Bitget CEO Gracy Chen says she suspects North Korean attackers exploited a backend system used to process wallet transactions to drain $387M from the platform
Another major hack has rattled the cryptocurrency world. On Thursday night, crypto exchange Bitget suffered a security breach …
Context & Ripple Effects
Bitget’s September 24 withdrawal halt followed unauthorized transfers from hot and warm wallets affecting roughly $351.6 million; by September 26, the company said the vulnerability had been identified and remediated. Chen’s attribution to North Korean attackers remains a suspicion, while Bitget says user funds are safe.
The incident fits a run of exchange compromises spanning different custody layers: Bybit reported a cold-wallet takeover in 2025, and subsequent reporting described employee-device manipulation and social engineering around its multisig controls. Bitget’s account instead concentrates attention on the backend systems that process wallet transactions.
First-order effects
- Bitget must restore withdrawals in phases while demonstrating that the remediated wallet-transaction backend can no longer authorize unauthorized transfers.
- The alleged $387 million drain and withdrawal freeze put Bitget’s assurances that customer funds are safe at the center of its customer and counterparty response.
Second-order effects
- Other exchanges’ security teams face pressure to audit transaction-processing backends alongside cold-wallet and multisig controls, after the earlier Bybit incident exposed a different route into custody operations.
- Institutional and retail customers have a clearer reason to judge exchanges on withdrawal continuity and incident response, not only on stated wallet-storage architecture.
Third-order effects
- Repeated failures across hot, warm, and cold-wallet environments point toward custody security becoming an operational-resilience test for centralized exchanges rather than a question of wallet type alone.
- If such breaches persist, the crypto sector’s legitimacy gap will be shaped increasingly by whether platforms can contain an attack and maintain credible access to customer funds.
The trend: Centralized crypto exchanges are being judged on end-to-end custody resilience, as attackers target both wallet controls and the systems that authorize transactions.