Cryptocurrency exchange Bitget says attackers stole hundreds of millions of dollars in digital assets from its internet-connected wallet infrastructure on September 24, 2026. Bitget's CEO says the attack is "highly consistent with known patterns of North Korean hacker organizations." The reported loss has changed as the count went on. Bitget first confirmed $351.6 million, a figure carried by TechCrunch, CNBC, SecurityWeek, Security Affairs and Cointelegraph. CEO Gracy Chen later gave an updated estimate of $387.5 million, reported by The Record and Decrypt. On either figure, this is the largest known crypto theft of 2026 so far. It is larger than the $292 million KelpDAO/LayerZero heist that SentinelOne attributes to the DPRK's TraderTraitor group. Withdrawals are suspended. Bitget says its User Protection Fund of more than $464 million will cover the losses in full. Mandiant and SlowMist are investigating.
What Happened
Bitget said its security systems flagged unauthorized transfers at 18:31 UTC on September 24, 2026 (Bitget statement via Security Affairs and Decrypt). The company started emergency response procedures and suspended crypto withdrawals. Deposits and trading continued as normal, according to Security Affairs. Bitget has not said when withdrawals will reopen (TechCrunch).
Accounts differ on which wallets were hit. Bitget's first statement and SecurityWeek describe "a limited number of hot wallets." Chen's later remarks, reported by CNBC, Security Affairs and Cointelegraph, say the attack reached "parts of its hot and warm wallet infrastructure." CNBC reports that Chen described 19 separate transfers. All sources agree that cold wallets were not touched. Bitget also says Bitget Wallet, its self-custodial product, runs on separate infrastructure and was not affected.
The loss figure grew in stages:
- Early on-chain estimates: blockchain analysts counted $175 million (The Record) to $183 million (CNBC, Decrypt) leaving Bitget-tagged wallets in roughly the first hour. Bitget later said those estimates had missed activity on some of the affected chains (CNBC).
- First confirmed figure: $351.6 million, which Bitget published when it went public.
- Updated figure: $387.5 million, which Chen gave during a town hall and livestream on September 25 (The Record, Decrypt).
Treat the total as provisional until Bitget publishes a final accounting.
Chen said the incident has been reported to law enforcement and to other crypto platforms. Several blockchain foundations and platforms have frozen wallet addresses linked to the attacker (SecurityWeek, The Record). Bitget has also announced a recovery bounty. According to The Record, platforms get 5% for voluntarily freezing attacker funds and 5% if funds are recovered. Cointelegraph reports that Chen said some stolen funds had already been recovered. No other source in this set confirms that.
What Was Taken
Only cryptocurrency was stolen. None of the sources report any exposure of customer personal data. The stolen assets were:
- Assets: ETH, XRP, BNB, AVAX, USDT and USDC (CNBC, SecurityWeek, Security Affairs)
- Networks: Ethereum, XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum (CNBC)
- Largest single-chain loss: XRP (SecurityWeek). Decrypt reports that about 103 million XRP, worth roughly $157 million, was taken. Bitget has not published a per-asset breakdown in the material reviewed here.
Bitget says customer balances are intact and that the platform will absorb the loss through its User Protection Fund. The fund holds more than $464 million, which is enough to cover even the higher $387.5 million estimate.
Why It Matters
Attribution is the victim's assessment, not a formal one. Chen cited three kinds of evidence: IP addresses that match "VPN choices by a certain DPRK group" (Cointelegraph, CNBC), behavioral patterns, and on-chain signatures (The Record). She did not name a specific group, and Bitget has not published its evidence (SecurityWeek). No government agency has attributed the attack yet. Cointelegraph reports that Chen said the company does not believe it was an inside job.
It fits a well-established pattern. North Korean actors were linked to about $2.02 billion in crypto theft in 2025, including the roughly $1.5 billion Bybit hack that the FBI attributed to the DPRK (Cointelegraph, SecurityWeek). TRM Labs puts North Korea behind about three-quarters of all crypto thefts in 2026 so far (TechCrunch).
The DPRK's reach goes beyond crypto firms. SentinelOne's September 18 research does not concern Bitget. It shows the Lazarus subgroup TraderTraitor (also tracked as UNC4899, Jade Sleet and PUKCHONG) using the same macOS backdoors seen in the LayerZero intrusion, FLATROOF and ROOFDECK, against a small IT services company with no crypto business. The group also plants malware in weaponized GitHub repositories used in fake job-recruitment lures, and delivers payloads through attacker-controlled Terraform provider registries. No source links TraderTraitor to the Bitget incident. The research does show that DPRK operators build access through suppliers and developers before they reach a high-value target.
The failure was in authorization, not key custody. The attacker did not need private keys. That undercuts a common assumption in exchange security: protecting keys is not enough if the system that decides what to sign can be manipulated.
The Attack Technique
Bitget says the initial intrusion method is still under investigation (CNBC, SecurityWeek, Cointelegraph). What the company has said so far:
- The attacker compromised a critical backend system inside Bitget's wallet infrastructure (SecurityWeek, CNBC, The Record).
- From that system, the attacker spoofed transaction data. Bitget's own authorization process then approved transfers that looked legitimate (Security Affairs, Decrypt).
- In Chen's words: "They did not forge user withdrawal requests, nor did they obtain our private keys of the cold wallet and any hot, warm wallet" (Cointelegraph, Decrypt).
- The Record reports that Chen said the attackers "exploited vulnerabilities" in the backend system. Those vulnerabilities have not been described publicly.
The approach resembles the Bybit (2025) and LayerZero (2026) heists. In both, attackers did not steal signing keys. They manipulated what legitimate signing or validation infrastructure was shown or approved. In the LayerZero case, SentinelOne says TraderTraitor combined a fake minting event with a DDoS against validation servers to get an illegitimate mint approved. That shows a strategy, not proof of who hit Bitget.
What Organizations Should Do
- Verify transfers independently of the system that requests them. Signing and approval services should recompute or independently check destination, amount and asset before approving. They should not trust metadata passed from upstream backend systems.
- Put limits and time delays on hot and warm wallets. Cap how much can leave per wallet and per time window, and require out-of-band human approval above set limits. Nineteen transfers across five chains should hit a hard stop well before $350M+ leaves.
- Hunt for known DPRK tradecraft. Check macOS developer and operations workstations for FLATROOF/macOS.Gaslight and ROOFDECK indicators. Audit Terraform lock files and provider sources for unapproved registries. Treat developers who ran code from recruiters or "take-home assessments" as potentially compromised.
- Isolate wallet backend infrastructure. Separate wallet orchestration systems from general corporate and engineering networks. Enforce phishing-resistant MFA and just-in-time access. Alert on logins through commercial VPN exit nodes, which were one of the clues Bitget cited.
- Prepare the freeze playbook in advance. Keep contacts at chain foundations, stablecoin issuers and peer exchanges on hand, so attacker addresses can be flagged within minutes. Bitget's partial freezes show how much this helps.
- Cover the financial exposure. Keep a reserve fund or insurance sized to your realistic worst-case hot and warm wallet exposure, and publish consistent loss figures as they firm up.
Sources: North Korean hackers suspected in $351M crypto theft, the largest s... | Don’t Call Us, We’ll Call Your APIs TraderTraitor Backdoors Resurf... | Crypto platform Bitget suspects North Korea in $352 million ... | North Korea Suspected in $351 Million Bitget Crypto Heist | Cryptocurrency exchange Bitget Says North Korea-Linked ... | Crypto CEO accuses North Korea of stealing $387 million ... | Bitget Hack Losses Climb to $387M: Here’s What Happened, and Why No... | Bitget Suspects North Korea Behind $352M Hack