A major security breach at crypto exchange Bitget has renewed fears about the safety of funds held on centralized platforms. The incident, which initially circulated as a hack on an unnamed exchange, was later confirmed to involve unauthorized transfers from Bitget hot wallets on September 24, resulting in a reported loss of $351.6 million.
Bitget stated that its cold wallets were not affected and that its User Protection Fund held more than $464 million to cover the loss. The exchange said it identified the attack method, fixed the vulnerability, and is working with security firms Mandiant and SlowMist to investigate.
Blockchain analytics firm Elliptic tied the attack to North Korean groups, noting that the Bitget incident pushed total North Korea-linked crypto theft above $1 billion in 2026. The breach has intensified the debate over whether investors should keep assets on centralized exchanges or shift to decentralized exchanges and cold wallets.
Broader market sentiment remains cautious, with traders watching for additional security updates and potential regulatory responses. The recurring pattern of hot and warm wallet compromises underscores systemic vulnerabilities in exchange infrastructure and highlights the need for stronger custody and security standards.