Bitget $352 million hack

Bitget $352 million hack is the central phrase for this report because it captures the specific development readers need to evaluate. Nineteen suspicious transfers drained several blockchains; the exchange says users will be covered, while its North Korea attribution remains preliminary.
What Bitget confirmed
Bitget said roughly $351.6 million was removed through 19 unauthorized transfers spanning several blockchains. Hot and warm wallet infrastructure was affected; the company said cold wallets and private keys remained secure. Withdrawals were paused while deposits and trading continued. XRP was the largest reported asset category, at roughly $120 million.
The protection-fund test
Chief executive Gracy Chen said Bitget’s user protection fund exceeded $464 million and that customers would be covered. That pledge is central because a reserve advertised for crises becomes meaningful only when claims are paid promptly, transparently and without forcing users to absorb hidden conversion losses. A rush to withdraw after service resumes could test liquidity as much as the theft tests solvency.
North Korea is an allegation, not a conclusion
Chen said on-chain patterns suggested North Korean state-linked actors. That attribution is preliminary and disputed. Blockchain traces can show movement, clustering and laundering behavior, but assigning a state sponsor usually also requires infrastructure evidence, operational overlap and intelligence unavailable to the public. This report does not treat the attribution as established fact.
Who gains and who loses
Cold-storage and self-custody advocates gain another example of the risks concentrated in exchange-controlled wallets. Chain-analysis and incident-response firms gain demand. Bitget faces reputational damage even if every user is reimbursed, while XRP sentiment may feel a short-term effect because it was the largest drained asset. Rival exchanges gain only if they can demonstrate stronger controls rather than exploit fear.
What happens next
The key evidence will be a wallet-by-wallet accounting, restoration of withdrawals, verified reimbursements and any recovery or freezing of stolen assets. Investigators also need to explain how 19 transfers crossed controls and whether one credential, one service or several systems failed. If the total holds, the theft will rank among 2026’s largest; the lasting verdict will depend on disclosure quality and customer outcomes, not the anniversary-week headline.
Related Signal Post News coverage
an earlier cross-chain key failure the regulatory debate around crypto market structure
Sources and reporting basis
Reporting note: This is a fixed September 25, 2026 snapshot. Attributed claims remain attributed; forecasts, polls, vendor results and early cyber findings can change as new evidence appears.