US Edition
Your source for latest news
TechnologyCybersecurity

Bitget hack exposes $351 million to suspected North Korean hackers, largest crypto theft of 2026

A backend compromise at the Seychelles-registered exchange let attackers spoof internal transfer data and drain hot wallets of ether, XRP and stablecoins, prompting a withdrawal freeze and pointing again to North Korea's expanding crypto-theft operation.

PT
By PressTemps Technology DeskPublished Today, 21:05 ET · 6 min read
Bitget hack exposes $351 million to suspected North Korean hackers, largest crypto theft of 2026
A padlock on a keyboard, illustrative of exchange cybersecurity (not a photo from the Bitget incident). Photo: FlyD / Unsplash.
What to know
Bitget said suspected North Korean hackers stole about $351.6 million from its hot and warm wallets on September 24, 2026, the largest single crypto theft of the year.
The attacker compromised a backend wallet system and spoofed transfer data to trigger Bitget's own authorization process, rather than stealing private keys; cold wallets were untouched.
Bitget suspended withdrawals but says the loss is fully covered by its $464 million User Protection Fund, and deposits and trading continued normally throughout.
Blockchain-analytics firm TRM Labs found North Korean-linked actors responsible for roughly 76 percent of global crypto-hacking losses in 2026, part of a multiyear pattern the FBI and U.S. Treasury have also documented.

Cryptocurrency exchange Bitget said suspected North Korean hackers stole approximately $351.6 million from its platform on Thursday, in what security researchers now count as the largest single cryptocurrency theft of 2026. The company detected unauthorized transfers from a portion of its hot and warm wallets at 18:31 UTC on September 24 and suspended withdrawals within minutes while it investigated, according to Bitget's official security notice.

Bitget said the attacker did not obtain private keys. Instead, the company said someone compromised a critical backend system inside its wallet infrastructure, used it to generate falsified transfer data, and then triggered the exchange's own authorization-signing process to move funds out under the appearance of legitimate transactions. The assets taken spanned ether, XRP, USDT, USDC, Avalanche and BNB, moved across the Ethereum, XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum networks, according to reporting by The Hacker News.

A backend compromise, not a stolen key

Bitget Chief Executive Gracy Chen said the exchange's cold wallets, which hold the bulk of customer assets and are kept off networked systems, were never touched, and that customer account balances remain accurate. Deposits and trading continued operating normally through the incident; only withdrawals were paused. The company said its three-tier wallet architecture, which separates cold, warm and hot storage, limited the breach to a slice of the warm and hot layers rather than exposing the platform's full reserves.

Chen linked the intrusion to North Korea based on forensic indicators rather than a public claim of responsibility.

"Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations," Chen said, according to TechCrunch.
Investigators traced connections from the intrusion to VPN infrastructure previously associated with North Korean hacking groups, and said the overall operational signature echoed earlier state-linked heists. Bitget brought in Google-owned incident-response firm Mandiant and blockchain security firm SlowMist to assist, and said it notified law enforcement.

The numbers behind the theft

Bitget said the roughly $351.6 million loss falls entirely within its User Protection Fund, a reserve the company says holds more than $464 million, equivalent to about 5,500 bitcoin, set aside specifically to make customers whole after exactly this kind of incident. The exchange has not committed to a firm timetable for restoring withdrawals, saying only that the pause "shouldn't take weeks," and it launched a fund-tracing and recovery bounty program to reward anyone who helps identify or freeze the stolen assets. Some blockchain foundations have already frozen wallet addresses linked to the attackers, according to Bitget's updates.

The theft surpasses the roughly $319 million drained from Blockstream's Liquid Network on September 6 and the $292 million and $285 million exploits of KelpDAO and Drift Protocol in April, making it the single largest crypto theft recorded so far in 2026. Those April incidents were also attributed to North Korean operators.

A pattern investigators know well

The Bitget incident fits a trend that blockchain-analytics firm TRM Labs has been tracking for years. In a research note published earlier this year, the firm found that North Korean-linked actors accounted for roughly 76 percent of all cryptocurrency hacking losses globally through the first four months of 2026, and that the country's share of global crypto-theft value has climbed steadily from under 10 percent in 2020 to 64 percent in 2025. TRM Labs puts cumulative North Korean-attributed crypto theft since 2017 at more than $6 billion, funds that United Nations investigators and Western governments say help finance Pyongyang's weapons programs in defiance of sanctions.

The FBI has documented the same actors and techniques before. After the $1.5 billion theft from exchange Bybit in February 2025, the bureau's Internet Crime Complaint Center formally attributed that attack to North Korea, describing the group's tactic, tracked under the name TraderTraitor, of compromising exchange infrastructure and signing processes to move funds that are then rapidly converted and laundered across thousands of addresses. The U.S. Treasury's Office of Foreign Assets Control has separately sanctioned individuals and shell companies it says helped launder proceeds from North Korean cyber operations, including a network of intermediaries the agency said funneled stolen and fraudulently earned funds toward the country's weapons programs.

Who is affected, and what happens next

Bitget customers are not able to withdraw funds while the exchange completes its security review, though the company says no user has lost money and balances remain intact on the platform's books. Independent crypto-security researchers, including analysts who track on-chain movement of stolen funds, are watching where the attackers attempt to launder the assets, typically through decentralized exchanges, cross-chain bridges and mixing services, before any conversion to cash. Bitget said it would publish a full incident report, including root-cause analysis and corrective measures, within 24 hours of the breach and would provide hourly updates in the meantime.

The incident is likely to renew scrutiny of exchange security practices more broadly, particularly the backend authorization systems that let hot wallets sign and release transactions automatically. Security researchers have noted that several of this year's largest thefts, including Bitget's, involved compromising the signing or approval workflow itself rather than stealing keys directly, a shift that exchanges will need to account for as they harden defenses against a threat actor that shows no sign of slowing down.

More on this story

All Technology