Skip to main content

Wallets and self-custody

The Bitget Hack Report and What an Exchange "Protection Fund" Actually Covers

A reported $352M hack at Bitget could consume most of its protection fund. Here is how exchange reserves, custody, and attribution really work.

7 min read25 September 2026CryptoBipto editorial

The Bitget Hack Report and What an Exchange "Protection Fund" Actually Covers

A crypto exchange is reported to have lost roughly $352 million in a single security incident. The number that matters more than the headline figure is a percentage: according to reporting from CryptoSlate, that loss could drain approximately 76% of Bitget's protection fund — the reserve the exchange set aside to make users whole if something went wrong.

That is the part worth slowing down for. Not the theft. The reserve.

Most people who keep coins on an exchange have a vague sense that there is "something" behind their balance — an insurance policy, a fund, a guarantee. Very few could tell you how big it is, what triggers a payout, who decides, or what happens when one incident eats three-quarters of it. This post is about that gap.

The report is recent and details are still unsettled. The attack vector has not been publicly confirmed, the attribution to North Korea-linked actors is not independently verified at the time of writing, and it is not yet clear whether all affected users will be fully compensated. Treat the specific figures as reported, not established.

You can read the summary of the report here: Bitget reportedly suffers a $352 million hack linked to North Korea. The original reporting is at CryptoSlate.

First, what "keeping crypto on an exchange" actually means

A centralized exchange is a company where you can buy, sell, and store cryptocurrency. You send it money or coins, and it shows you a balance.

Here is the mechanical detail most people miss: that balance is a number in the exchange's database. It is not your coins sitting in your own wallet on a blockchain. The exchange holds the actual crypto in wallets it controls, pooled across all its customers, and keeps an internal ledger of who is owed what.

This arrangement is called custodial. The exchange has custody. You have a claim.

The alternative is self-custody, where you hold the private keys yourself — a private key being the secret string that authorizes a transaction on a blockchain. Whoever holds the key controls the coins. That is the whole security model of a blockchain, and it does not care whether the key holder is you, an exchange, or someone who stole it.

This is why exchange hacks are different from, say, a hacked email account. When an attacker obtains the keys to an exchange's wallet, the resulting transactions are valid. The blockchain does exactly what it was designed to do. There is no fraud department that can reverse it.

So what is a protection fund?

A protection fund (sometimes called an insurance fund, a reserve fund, or a SAFU fund depending on the exchange) is a pool of assets the exchange voluntarily sets aside to reimburse users after an incident.

It is often compared to bank deposit insurance. The comparison is useful for explaining the idea and misleading for almost everything else. A few differences worth holding onto:

Bank deposit insuranceExchange protection fund
Who backs itTypically a government or statutory schemeThe exchange itself
Is it requiredUsually mandatory for licensed banksVoluntary
Coverage limitDefined per depositor, published in lawDefined by the exchange, if defined at all
Payout triggerSet by statute and regulatorSet by the exchange
If it runs outBackstopped by the scheme or stateIt has run out

That last row is the one the Bitget report puts in the spotlight. A protection fund is finite. It has a balance. If a single incident consumes roughly 76% of it, then whatever is left is what stands behind everyone for the next incident.

None of this means a protection fund is worthless. A funded reserve is meaningfully better than no reserve. But it is a corporate commitment, not a legal guarantee, and its usefulness depends on three things most users never check: how large it is, what assets it is held in, and under what conditions the exchange says it will pay.

An exchange that publishes all three is telling you something. So is one that does not.

Big thefts are rarely broken cryptography

When a large amount of crypto disappears, the instinctive assumption is that someone broke the encryption. That is almost never what happened.

The pattern in the largest recorded incidents is that attackers got the authorization — the keys, or the humans who control them — rather than defeating the math.

The Bybit hack in February 2025 is the clearest recent example. It was the largest crypto theft on record at the time, involving hundreds of thousands of ether. The attackers manipulated the screen that Bybit's staff used to approve a routine transfer. The staff saw what looked like a normal operation, approved it, and in doing so handed over control of a cold wallet. Every signature was legitimate. The people producing them had been shown a lie.

The Ronin Bridge hack in March 2022 followed a related logic. Ronin is the network built for the game Axie Infinity, and the bridge connected it to Ethereum. A bridge of that design is secured by a set of signing keys — a required number of approvals before funds move. The attackers, whom the FBI linked to North Korea's Lazarus Group, obtained control of enough of those keys to approve their own withdrawals. It remains one of the largest thefts in crypto's history.

And going back further, The DAO hack in June 2016 showed the third variant: not stolen keys, but flawed code. The DAO was an early investment fund run by smart contracts on Ethereum, and a bug in it let an attacker drain about 3.6 million ETH. Ethereum's response — reversing the theft by changing the chain's history — was so contentious that the network split in two, into Ethereum and Ethereum Classic.

Three different mechanisms: deceived humans, captured keys, broken code. The cryptography held in all three.

If you want to go deeper on how these attacks are constructed and what the recurring patterns look like, our lesson on DeFi scams, rug pulls, drainers and major hacks covers the ground systematically.

The North Korea attribution, and why it keeps appearing

North Korean state-linked hacking groups have been identified by multiple governments and cybersecurity firms as responsible for billions of dollars in cryptocurrency theft over recent years. These operations are widely believed to fund the country's weapons programs. Exchanges, bridges, and DeFi protocols have all been targeted, and the scale and sophistication of the attacks have grown over time.

A word on attribution itself, because it is frequently reported as if it were a fact established on day one.

Attribution is inference. Investigators look at how stolen funds are moved, which wallets and laundering services they pass through, what tooling and infrastructure the attackers reused, and how the operation resembles previous ones. A confident attribution usually emerges over weeks, from multiple independent parties, not from an initial report.

In the Bitget case, the North Korea link is reported but, at the time of writing, not independently confirmed. In the Ronin case, the FBI's link to the Lazarus Group came later and from a government investigation. The difference between "reported as linked to" and "attributed by investigators" is real, and it is worth noticing which one you are reading.

The questions this incident actually raises

This is not a recommendation about where to keep anything. It is a list of the things this story makes legible, which are usually invisible.

How much of a protection fund is disclosed, and in what form? A fund denominated in volatile assets is worth a different amount on the day you need it than on the day it was announced. A fund whose size is asserted but not verifiable is a claim about a number, not a number.

What triggers a payout? Many funds are described in marketing language rather than contractual language. "We will use this fund to protect users" and "you are entitled to compensation of X under conditions Y" are very different sentences.

What is left after a large incident? This is the specific question the reported 76% figure raises. A reserve is a shock absorber, and a shock absorber that has already absorbed most of one shock is in a different state than an unused one.

What is the trade-off in the alternative? Self-custody removes exposure to a single company's security and solvency. It replaces that with full personal responsibility for key management — lost keys, phishing, and drainer approvals are all real and all permanent. Neither option is universally safer. They fail in different ways, and the failure modes are worth understanding before an incident rather than during one.

The durable lesson here is not about one exchange. It is that in custodial crypto, your balance is a promise from a company, and the strength of that promise depends on things that are usually written in small print or not written at all. The Bitget report is a prompt to go read them.


This article is educational and is not financial, investment, legal, or security advice. CryptoBipto does not custody funds, execute trades, or recommend any exchange, asset, or product. Details of the incident described are as reported and may change as more information becomes available.

CryptoBipto — editorial standards

Start at the level that suits you and learn at your own pace.