Bitget Says $351.6M Hot Wallet Exploit Hit Exchange as Coinbase Hack Claims Fly

Daily Feed
Bitget Says $351.6M Hot Wallet Exploit Hit Exchange as Coinbase Hack Claims Fly

Bitget says a major exploit hit its hot wallets and affected about $351.6 million in assets, while a separate public fight over Coinbase has revived old questions about how much crypto firms disclose when things go wrong.

  • Bitget says user funds are protected and cold wallets were not compromised.
  • TRM Labs estimates about $351.6 million moved in the exploit.
  • North Korea-linked tactics are suspected, but not definitively proven in the supplied research.
  • THORChain is again under pressure after some stolen funds moved through it.
  • Coinbase denies hiding repeated hacks; the public allegations remain unverified.

Bitget said on September 24 that its security systems “identified unauthorized transfers involving a limited number of hot wallets.” Hot wallets are the online ones exchanges use for active trading and withdrawals. They’re convenient. They’re also the part of the castle that gets hit first when someone brings a battering ram and knows where the door hinges are.

According to TRM Labs, the incident involved an estimated USD 351.6 million moved from Bitget’s hot and warm wallets across several chains, including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain, and Base. Warm wallets sit between hot and cold storage: less exposed than hot wallets, but still online enough to matter. Bitget later said the loss fell within its User Protection Fund, which held $464 million at the time, and that cold wallets were not affected.

That distinction matters. Cold wallets are kept offline, which is why exchanges treat them as the last line of defense. If those stay untouched, the breach is still ugly, but it is not the absolute worst-case scenario. In crypto security, that’s a little like saying the building only burned down to the second floor.

Bitget temporarily suspended withdrawals after the incident, then began a phased resumption on September 28. The exchange said it hoped to have withdrawals and peer-to-peer transactions for all tokens restored by Friday, October 2. It also launched a recovery bounty program offering 5% of frozen or recovered funds in eligible cases. That bounty does not apply when courts or law enforcement order a freeze or recovery.

Bitget CEO Gracy Chen said the attack was “very likely” North Korea-linked. In her account, the pattern matched techniques used by DPRK-aligned hackers. She told The Block that private keys and cold wallets were not compromised, and said attackers used a zero-day vulnerability in a third-party security product to obtain high-level internal credentials.

A zero-day is a flaw the vendor does not know about yet, which means there is no patch available when the attackers arrive. If that account holds up, the weak point was not just wallet custody. It was the machinery around it: access controls, internal approval flows, and backend systems that were supposed to keep bad withdrawal commands out.

Security firm Slowmist added more detail, saying the attackers began exploiting the zero-day on August 31 and used a “highly customized withdrawal tool” built for the wallet system’s logic. Slowmist said the tool “forged risk-control parameters” and “constructed withdrawal requests, ” and even suggested that two fabricated BTC withdrawal orders may have caused the attackers to miss stealing even more. That is the sort of breach that feels less like vandalism and more like someone reverse-engineered the entire checkout line.

The stolen assets reportedly included ETH, USDT, USDC, BNB, XRP, and others. Bitget said the largest single-chain loss was XRP, worth roughly $83 million. Circle and Tether together froze roughly $318, 000 worth of their tokens. Useful? Sure. Meaningful against hundreds of millions? Not exactly. Crypto thieves move fast; freezes often arrive after the money has already crossed several chains and a few time zones.

Some of the stolen funds were moved through THORChain, a cross-chain bridging platform that lets users move value between blockchains. Bitget’s CEO publicly asked THORChain “to refuse service to these addresses.” THORChain developers responded that the system is “decentralized and permissionless” and therefore cannot selectively freeze funds.

That defense is coherent. It is also why THORChain keeps getting dragged into laundering fights. If a protocol is built to avoid censorship, it cannot easily pick and choose who gets blocked when stolen funds show up. That’s the trade-off. Freedom is a feature, but so is the fact that criminals notice open railings too.

TRM Labs said the Bitget exploit is the largest crypto theft of 2026 by value so far. It described the attack as likely North Korea-linked, but not definitively attributed. That caution matters. In crypto, “looks like Lazarus” can slide into “Lazarus definitely did it” faster than a meme coin can get a Binance listing.

The North Korea angle is not random speculation. DPRK-linked groups have a long record of targeting crypto because digital assets can be moved, split, bridged, and converted quickly. The North Korean Cyber Operations: Crypto Theft and Global notes that these operations often overlap across units and aliases, while the FBI attributed the Bybit hack to TraderTraitor, a subunit of the regime’s cyber apparatus. The basic playbook is familiar: steal, obfuscate, convert, and cash out before anyone can build a clean trail.

That same laundering pattern is why bridges, decentralized exchanges, and swap services keep getting caught in the blast radius. Once a theft happens, the real race is not just against the exchange that got hit. It is against every venue that might help the money move one step farther from the crime scene.

The Coinbase dispute is a different beast, and it should stay separate from the Bitget exploit unless new evidence changes the picture.

On September 27, Jordan “Cobie” Fish replied to an X user claiming Coinbase had “stole $1, 200, 000 from me, ” dismissing it as a “shitcoin” promotion and a “fake/scam report/engagement farm.” Then Ari Paul, co-founder of BlockTower Capital, weighed in with a much more serious allegation. He said Coinbase had “lost” $25 million of his firm’s funds a couple years ago and was “covering up massive and repeated hacks.” Paul claimed he had traced the problem to at least a dozen other affected firms and over $1 billion supposedly hidden from view.

Coinbase Battles North Korean Hackers in High-Stakes Crypto has already put the exchange’s security fight under the microscope, and Coinbase Support responded plainly: “Coinbase is not hiding a series of hacks and we certainly didn’t lose $1B.” That is the only firm conclusion available from the material at hand: Coinbase denies the allegation. Everything else in that dispute remains contested.

Paul said he could not share proof yet because legal processes were still unfolding, and later said Coinbase had tried, unsuccessfully, to sue him into silence. Former Coinbase executive Justin Mart pushed back, suggesting the problem may have involved compromised BlockTower credentials rather than some broader exchange cover-up. He also said the claims would require significant proof.

Paul later said BlockTower “ultimately traced the hack to a specific Coinbase codebase” and to the “same attacker”, likely Lazarus, though he said he was “not 100% sure.” He also said he would release a full dossier if Coinbase agreed not to harass or sue him. That is a claim about proof, not proof itself. The crypto industry has seen enough dramatic posts that “trust me, I’ve got receipts” no longer moves the needle by itself.

For readers trying to sort the noise from the substance, the difference between the two situations is straightforward:

Bitget’s incident is supported by technical reporting. TRM Labs provides a concrete estimate, describes the wallets affected, and says the pattern is likely North Korea-linked.

The Coinbase allegations are still unproven. There is a public dispute, a denial, and competing theories, but no verified evidence in the supplied material confirming a hidden series of hacks or more than $1 billion in covered-up losses.

Key takeaways

  • Was Bitget’s cold storage compromised?
    Bitget says no, and the supplied research supports that cold wallets were not affected. The breach hit hot and warm wallet infrastructure, which is exactly why exchanges keep online liquidity under constant risk.
  • Is the North Korea attribution definitive?
    No. The evidence points to a likely DPRK-linked operation, but the supplied research stops short of a courtroom-level attribution.
  • Why is THORChain being criticized again?
    Because stolen funds reportedly moved through it. THORChain says it is decentralized and permissionless, so it cannot selectively freeze addresses without changing the protocol’s design.
  • Did Coinbase admit to hiding hacks?
    No. Coinbase denied the claim, and the allegation remains unverified in the material provided.
  • What’s the bigger lesson?
    Exchange security failures often start in the operational layer, not just private keys. And once stolen crypto starts moving across chains, decentralized rails can be either neutral infrastructure or a laundering machine, depending on who is using them.

Coinbase Bolsters Security with US-Centric Rules to Combat shows how exchanges are trying to harden themselves after years of watching attackers treat crypto firms like an all-you-can-drain buffet. Bitget shows how a sophisticated exploit can hit the operational layer even when cold storage stays intact. Coinbase shows how quickly a public accusation can turn into a reputational firefight when the facts are still cloudy and everyone has an incentive to spin.

That is the part crypto keeps relearning the hard way: the tech can be elegant, but the systems around it are full of weak spots, human error, and actors who treat opacity as a business model. Decentralization is not a magic shield. It is a design choice, one that works beautifully when used honestly, and very differently when the bad guys show up with a wallet-draining plan.

Further reading

A few useful angles on the exchange breach, wallet security, and the Coinbase dust-up:

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog