/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Bitget CEO Gracy Chen says she suspects North Korean attackers exploited a backend system used to process wallet transactions to drain $387M from the platform

Another major hack has rattled the cryptocurrency world.  On Thursday night, crypto exchange Bitget suffered a security breach …

Fortune Camila Grigera Naón

Context & Ripple Effects

Bitget’s September 24 withdrawal halt followed unauthorized transfers from hot and warm wallets affecting roughly $351.6 million; by September 26, the company said the vulnerability had been identified and remediated. Chen’s attribution to North Korean attackers remains a suspicion, while Bitget says user funds are safe.

The incident fits a run of exchange compromises spanning different custody layers: Bybit reported a cold-wallet takeover in 2025, and subsequent reporting described employee-device manipulation and social engineering around its multisig controls. Bitget’s account instead concentrates attention on the backend systems that process wallet transactions.

First-order effects

  • Bitget must restore withdrawals in phases while demonstrating that the remediated wallet-transaction backend can no longer authorize unauthorized transfers.
  • The alleged $387 million drain and withdrawal freeze put Bitget’s assurances that customer funds are safe at the center of its customer and counterparty response.

Second-order effects

  • Other exchanges’ security teams face pressure to audit transaction-processing backends alongside cold-wallet and multisig controls, after the earlier Bybit incident exposed a different route into custody operations.
  • Institutional and retail customers have a clearer reason to judge exchanges on withdrawal continuity and incident response, not only on stated wallet-storage architecture.

Third-order effects

  • Repeated failures across hot, warm, and cold-wallet environments point toward custody security becoming an operational-resilience test for centralized exchanges rather than a question of wallet type alone.
  • If such breaches persist, the crypto sector’s legitimacy gap will be shaped increasingly by whether platforms can contain an attack and maintain credible access to customer funds.

The trend: Centralized crypto exchanges are being judged on end-to-end custody resilience, as attackers target both wallet controls and the systems that authorize transactions.

Discussion

  • @gracybitget @gracybitget on x
    Here is what we can confirm at this stage: On the attack: Our security team has made initial progress in tracing the source. The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization pro…
  • @gracybitget @gracybitget on x
    Earlier 7 hours ago, I hosted a live stream with everyone that lasted over three hours. Here's a summary of the points I covered in the live: ① Bitget security incident update — 1 hours in. We're sharing specific facts, not just reassurances. ② Affected assets include ETH, XRP (t…
  • @gracybitget @gracybitget on x
    Within 24 hours of the September 24 (UTC) incident: here is our further update as promised. Our investigation with Mandiant and SlowMist is ongoing — thorough forensic analysis takes more than 24 hours, and further findings will be shared as they become available. Three key updat…
  • @bitget @bitget on x
    Bitget will begin resuming withdrawals in orderly phases following the security incident identified on September 24. The vulnerability involved in the incident has been identified and remediated. Bitget's security and technical teams have since been conducting additional validati…
  • @gracybitget @gracybitget on x
    Bitget will begin resuming withdrawals in orderly phases following the security incident on Sep 24. Thank you all for your patience. Please understand that due to the different nature of this incident (which involves multiple blockchains and multiple cryptocurrencies), we are tak…
  • @bitget @bitget on x
    Live about Bitget Hot Wallet Incident on September 24, 2026 https://x.com/...