Bitget crypto exchange loses $351.6 million in suspected North Korean heist (2026)
Cryptocurrency exchange Bitget said suspected North Korean attackers spoofed transaction data through a compromised backend to drain about $351.6 million from its hot and warm wallets.
- Victim
- Bitget
- Loss
- $351.6M
On 25 September 2026, cryptocurrency exchange Bitget โ a global platform registered in Seychelles โ confirmed that attackers had stolen roughly $351.6 million in digital assets after compromising part of its wallet backend. The exchange's security systems first flagged the unauthorized transfers at 18:31 UTC on 24 September, and Bitget said the losses spanned its hot and warm wallets across multiple blockchains, including Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Smart Chain, and Base, affecting assets such as ETH, XRP, BNB, AVAX, USDT, and USDC.
What happened
According to CEO Gracy Chen, the attackers did not steal private keys. Instead, they broke into a critical backend system inside Bitget's wallet infrastructure, fed forged transfer data into the exchange's own approval process, and moved funds out as if the payouts were routine. That distinction matters: rather than defeating cryptography, the intruders subverted the trusted plumbing that validates and signs transactions. Bitget said its cold wallets and the overwhelming majority of platform assets remained secure and unaffected.
The exchange temporarily suspended withdrawals while it conducted a comprehensive security review, and it engaged Google-owned Mandiant and blockchain forensics firm SlowMist to investigate. Chen said Bitget's User Protection Fund โ reported to hold more than $464 million โ was large enough to absorb the loss, so affected customers would be made whole.
Attribution
Blockchain intelligence firm TRM Labs reported multiple overlaps between the wallets used to launder the stolen Bitget funds and infrastructure tied to earlier North Korean thefts, including the record Bybit heist and the AFX Bridge attack. Those overlaps, TRM said, point to the DPRK-linked cluster tracked as TraderTraitor, part of the broader Lazarus crypto-theft campaign. If the attribution holds, the incident ranks among the largest cryptocurrency thefts of the year.
Why it matters
The Bitget case underscores a shift in how crypto exchanges are being attacked. As platforms harden key management and adopt multi-signature controls, sophisticated state-backed groups are increasingly targeting the backend systems that generate and authorize transactions โ turning an exchange's own trusted processes into the theft mechanism. It is a reminder that securing the signing infrastructure is only as strong as the integrity of the data that infrastructure is asked to sign.
Timeline
Bitget's security systems flag unauthorized transfers out of its hot and warm wallets at 18:31 UTC.
Bitget publicly confirms the theft of about $351.6 million, suspends withdrawals, and attributes the attack to suspected North Korean actors.
Sources
- coindesk.comhttps://www.coindesk.com/markets/2026/09/25/bitget-s-usd351-million-hack-happened-via-spoofed-transfers-not-private-keys-ceo-gray-chen-says
- thehackernews.comhttps://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/
- scworld.comhttps://www.scworld.com/brief/bitget-loses-351-6-million-in-suspected-north-korean-crypto-hack