Bitget says attackers drained $387.5M from hot and warm wallets on September 24 after compromising critical backend infrastructure. Withdrawals remain suspended; Bitget claims its protection fund covers the loss and cold wallets stayed secure.

  • Security systems detected unauthorized transfers at 18:31 UTC, but public confirmation arrived nearly three hours later
  • A fresh wallet spent $19.67M USDT0 on 7,111 ETH, paying premiums up to 5%
  • At 00:43 UTC, CEO Gracy Chen said falsified transaction data fooled internal authorization; suspected North Korean involvement remains unconfirmed

This was not reported as private-key theft—it was a breakdown in transaction approval. Traders should wait for withdrawals, verified reimbursements, and a full Mandiant-SlowMist postmortem before trusting the recovery narrative.