Bitget hack exposes $351 million to suspected North Korean hackers, largest crypto theft of 2026
A backend compromise at the Seychelles-registered exchange let attackers spoof internal transfer data and drain hot wallets of ether, XRP and stablecoins, prompting a withdrawal freeze and pointing again to North Korea's expanding crypto-theft operation.
Cryptocurrency exchange Bitget said suspected North Korean hackers stole approximately $351.6 million from its platform on Thursday, in what security researchers now count as the largest single cryptocurrency theft of 2026. The company detected unauthorized transfers from a portion of its hot and warm wallets at 18:31 UTC on September 24 and suspended withdrawals within minutes while it investigated, according to Bitget's official security notice.
Bitget said the attacker did not obtain private keys. Instead, the company said someone compromised a critical backend system inside its wallet infrastructure, used it to generate falsified transfer data, and then triggered the exchange's own authorization-signing process to move funds out under the appearance of legitimate transactions. The assets taken spanned ether, XRP, USDT, USDC, Avalanche and BNB, moved across the Ethereum, XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum networks, according to reporting by The Hacker News.
A backend compromise, not a stolen key
Bitget Chief Executive Gracy Chen said the exchange's cold wallets, which hold the bulk of customer assets and are kept off networked systems, were never touched, and that customer account balances remain accurate. Deposits and trading continued operating normally through the incident; only withdrawals were paused. The company said its three-tier wallet architecture, which separates cold, warm and hot storage, limited the breach to a slice of the warm and hot layers rather than exposing the platform's full reserves.
Chen linked the intrusion to North Korea based on forensic indicators rather than a public claim of responsibility.
"Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations," Chen said, according to TechCrunch.Investigators traced connections from the intrusion to VPN infrastructure previously associated with North Korean hacking groups, and said the overall operational signature echoed earlier state-linked heists. Bitget brought in Google-owned incident-response firm Mandiant and blockchain security firm SlowMist to assist, and said it notified law enforcement.
The numbers behind the theft
Bitget said the roughly $351.6 million loss falls entirely within its User Protection Fund, a reserve the company says holds more than $464 million, equivalent to about 5,500 bitcoin, set aside specifically to make customers whole after exactly this kind of incident. The exchange has not committed to a firm timetable for restoring withdrawals, saying only that the pause "shouldn't take weeks," and it launched a fund-tracing and recovery bounty program to reward anyone who helps identify or freeze the stolen assets. Some blockchain foundations have already frozen wallet addresses linked to the attackers, according to Bitget's updates.
The theft surpasses the roughly $319 million drained from Blockstream's Liquid Network on September 6 and the $292 million and $285 million exploits of KelpDAO and Drift Protocol in April, making it the single largest crypto theft recorded so far in 2026. Those April incidents were also attributed to North Korean operators.
A pattern investigators know well
The Bitget incident fits a trend that blockchain-analytics firm TRM Labs has been tracking for years. In a research note published earlier this year, the firm found that North Korean-linked actors accounted for roughly 76 percent of all cryptocurrency hacking losses globally through the first four months of 2026, and that the country's share of global crypto-theft value has climbed steadily from under 10 percent in 2020 to 64 percent in 2025. TRM Labs puts cumulative North Korean-attributed crypto theft since 2017 at more than $6 billion, funds that United Nations investigators and Western governments say help finance Pyongyang's weapons programs in defiance of sanctions.
The FBI has documented the same actors and techniques before. After the $1.5 billion theft from exchange Bybit in February 2025, the bureau's Internet Crime Complaint Center formally attributed that attack to North Korea, describing the group's tactic, tracked under the name TraderTraitor, of compromising exchange infrastructure and signing processes to move funds that are then rapidly converted and laundered across thousands of addresses. The U.S. Treasury's Office of Foreign Assets Control has separately sanctioned individuals and shell companies it says helped launder proceeds from North Korean cyber operations, including a network of intermediaries the agency said funneled stolen and fraudulently earned funds toward the country's weapons programs.
Who is affected, and what happens next
Bitget customers are not able to withdraw funds while the exchange completes its security review, though the company says no user has lost money and balances remain intact on the platform's books. Independent crypto-security researchers, including analysts who track on-chain movement of stolen funds, are watching where the attackers attempt to launder the assets, typically through decentralized exchanges, cross-chain bridges and mixing services, before any conversion to cash. Bitget said it would publish a full incident report, including root-cause analysis and corrective measures, within 24 hours of the breach and would provide hourly updates in the meantime.
The incident is likely to renew scrutiny of exchange security practices more broadly, particularly the backend authorization systems that let hot wallets sign and release transactions automatically. Security researchers have noted that several of this year's largest thefts, including Bitget's, involved compromising the signing or approval workflow itself rather than stealing keys directly, a shift that exchanges will need to account for as they harden defenses against a threat actor that shows no sign of slowing down.
Bitget Support Center — [SECURITY NOTICE] Bitget Hot Wallet Incident, September 24, 2026
The Hacker News — Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
TRM Labs — North Korea Stole 76% of All Crypto Hack Value in 2026 — With Just Two Attacks
FBI Internet Crime Complaint Center — North Korea Responsible for $1.5 Billion Bybit Hack

Anthropic Says Its Claude AI Agents Autonomously Found a New CRISPR-Like Enzyme System

Google to launch its first satellite carrying AI chips into orbit on Oct. 1
