Bitget exchange CEO Gracy Chen has confirmed that the $351.6M loss has been contained, and that no further authorized transfers are possible.
In an update on X, Chen said attackers had breached Bitget’s backend wallet infrastructure and fooled its authorization process. She said the exchange had since addressed that breach.
Private key compromise has been ruled out-this excludes the more severe risk scenarios. Loss containment is confirmed. No further unauthorized transfers are possible.
That distinction offered some relief. Stolen private keys could have given attackers continued control over the affected wallets. Still, Bitget had not set a date for restoring withdrawals.
Withdrawal restoration is being prepared in parallel. We will announce a timeline as soon as one is confirmed — we will not commit to a window we cannot guarantee.

Bitget hack update: $157M XRP lost amid Lazarus Group links
The security breach was first reported at 18:31 UTC on September 24. Out of the stolen assets, XRP accounted for nearly half of the heist at $157.4M. Ethereum [ETH], USDT, and USDC were also some of the top targeted assets, collectively accounting for +$140M of the stolen stash.


Already, the attacker has begun swapping the funds into EVM chains via multiple wallets to obscure and launder them. So far, $163M has been swapped to ETH, according to on-chain data.
Was the Bitget hack linked to Lazarus?
In her live update on X earlier, Chen said that the attack was likely carried out by a North Korean group, citing a key IP address pattern.
We think it is very likely a North Korean group; it’s not internal. We’ve identified some IP addresses that match the VPN choices by a certain DPRK group.
Interestingly, Web3 security analyst Specter traced and linked the Bitget stolen XRP to the July AFX hack, which was carried out by the notorious Lazarus group.


That said, the exchange had earlier stated that it has user protection funds that surpass $464M, noting that it is sufficient to cover the recent loss.
In fact, even Bybit CEO Ben Zhou had reached out to offer help to their colleagues, including helping them track and tag the attackers’ wallets. In other words, users will likely be refunded fully.
However, the incident is the second-largest centralized exchange breach after last year’s Bybit $1.5B breach. These high-value breaches are mainly handled by Lazarus Group.
But this further highlights how large centralized exchanges are increasingly being targeted by attackers, and calls for investor caution.
Final Summary
- Bitget CEO said there were no stolen private keys and confirmed the loss has been contained
- The $352M hack has been linked to the Lazarus Group, the attacker behind Bybit’s $1.5B breach




