Bitget, the cryptocurrency exchange, has confirmed that attackers drained roughly $387.5 million from its company-controlled wallets in a breach that the platform first detected at 18:31 UTC on September 24, 2026. The incident now ranks as the largest cryptocurrency hack of the year to date, and the exchange's chief executive has publicly pointed the finger at hackers linked to North Korea. No customer private keys were taken, and the company says its own internal approval machinery was turned against it.
The mechanics matter as much as the money. Centralized exchanges hold user assets in several kinds of pools: cold wallets kept offline, hot wallets connected to the internet for daily operations, and warm wallets that sit in between. Moving funds out of those pools normally requires a chain of internal checks, and Bitget says the attackers never broke the cryptography that protects the wallets. Instead, they entered a backend system that processes wallet transactions and fed it forged data, so payouts that should have been blocked were authorized as if they were routine.
North Korea has become the dominant state-level threat in crypto. Blockchain analytics cited by Bitget and other firms have for years tied a steady stream of exchange breaches to groups tracked as Lazarus Group, and 2025 was a record year: North Korean-linked hackers stole about $2 billion in crypto, according to Chainalysis. Investigators say the groups increasingly place information technology workers inside target companies, sometimes posing as recruiters, to gain the access that makes an attack like this one possible.
The Bitget breach did not happen in a quiet market. Earlier in September the Liquid Network lost $319 million, and in late July the hardware wallet Coldcard was drained of about $116 million. Within hours of the Bitget disclosure, on-chain investigators were already chasing funds across multiple chains, and rival platforms were freezing addresses tied to the attacker.
Key Facts
Bitget's security systems flagged unauthorized transfers leaving certain hot wallets at 18:31 UTC on September 24. Within about an hour, on-chain investigators had tallied roughly $183 million in stablecoins, Ethereum and other assets moving out of wallets tagged as belonging to the exchange, according to Decrypt, which reported on September 25 that the total was first put at $351.6 million and later revised to $387.5 million. Fortune reported on September 25 that the revised figure reflected additional transactions identified on networks including privacy-focused Zcash and TRON.
CEO Gracy Chen said in a three-hour livestream on X that the attackers did not forge user withdrawal requests and did not obtain private keys for the cold wallet or any hot or warm wallet. Instead, they compromised a backend system inside Bitget's wallet infrastructure and used it to spoof transaction data, tricking the exchange's authorization process into approving payouts that looked routine. The Record reported on September 25 that Chen described the evidence as linking the theft to hackers from North Korea, while stressing that the attacker's identity is not formally confirmed and no technical evidence has been published.
The largest single slice of the haul was about 102.93 million XRP, worth roughly $157 million, with 31,890 ETH worth about $86 million behind it, according to tracing cited by Startup Fortune. Funds moved across Ethereum, the XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum, and the revised count added ZEC, XAUt and TRX to the previously confirmed ETH, XRP, USDT and BNB. Startup Fortune reported on September 26 that about 6,300 ETH, close to $19 million, was funneled into the mixer Tornado Cash within hours, echoing the laundering pattern seen in previous North Korean operations.
Bitget said its User Protection Fund holds more than $464 million, enough to cover the loss, so customer account balances stay intact. BGB, the exchange's native token, fell almost 7% to $1.93 before recovering to $1.97. Deposits and trading continued while withdrawals were frozen, and Bitget pledged to publish a concrete resumption plan by 4:00 UTC on September 26, which is noon Beijing time. The exchange brought in Mandiant and SlowMist to investigate, notified law enforcement and other platforms, launched a real-time tracking dashboard and opened a recovery bounty that pays 5% for funds that platforms voluntarily freeze and 5% for funds recovered.
Analysis
What this really means is that the perimeter crypto exchanges have spent a decade hardening is not where this class of attacker is now going. Private keys, multi-signature schemes and cold storage have become genuinely difficult to defeat. So the attackers did not defeat them. They attacked the software that decides which transfers are legitimate, and that software approved the theft on Bitget's behalf. A signature produced by the victim's own authorization pipeline is, to the rest of the system, indistinguishable from a routine payout.
The revised loss figure is itself a warning. The tally climbed from $351.6 million to $387.5 million as investigators widened tracing to more networks and more asset types, which suggests that the first number any exchange publishes after a breach is a floor, not a final count. Decrypt reported on September 25 that a pseudonymous researcher flagged a freshly created wallet that spent $19.67 million in USDT0 to buy 7,111 ETH in six minutes, paying about 5% above market through UniswapX and 1inch Fusion. That is speed and slippage tolerated only by someone who expects to be chased.
Chen's attribution deserves scrutiny as well as respect. She cited IP addresses matching the VPN choices of what she called a certain DPRK group, along with behavioral patterns and on-chain signatures, and other experts found links to Lazarus Group. But she also conceded the attacker's identity is not confirmed, and no technical evidence was published alongside the claim. Attribution in crypto theft is a probabilistic art built on infrastructure reuse and money-flow habits, and it can be wrong.
The operational response has been unusually coordinated. Several blockchain foundations and exchanges have already frozen addresses tied to the attacker, and the bounty structure gives platforms a financial reason to act quickly rather than wait for legal guidance. Every dollar frozen before it reaches a mixer reduces what the User Protection Fund must absorb, and the fund's cushion of more than $464 million gives Bitget room that smaller exchanges simply do not have. The bigger picture here is that this is a fight over time, because the attacker's window to launder shrinks with every platform that moves first.
Why It Matters
Elliptic says the Bitget theft is the largest single suspected North Korean crypto heist of 2026 and pushes the regime's cumulative haul for the year past $1 billion, a figure reported via Bloomberg. That matters beyond one exchange's balance sheet. Proceeds from these operations are widely assessed to fund state programs, which turns each successful breach into a national revenue stream rather than an isolated crime. North Korea's 2025 total of about $2 billion, per Chainalysis, already showed the scale, and 2026 is now tracking toward matching or exceeding it with a quarter of the year still to run.
For ordinary users, the practical lesson is narrower. Bitget says customer balances are intact and that the self-custodial Bitget Wallet was not affected, because the unauthorized transfers were limited to company-controlled hot and warm wallets. But the incident shows that an exchange can lose nearly $400 million without a single private key leaving its vaults, which undermines the assumption that custody security begins and ends with key management. The internal tooling that validates payouts is now a first-class attack surface, and it is likely to be scrutinized across the industry in the coming weeks.
The market reaction was contained, at least at first: BGB's roughly 7% slide and partial recovery suggests traders priced in the protection fund rather than a solvency shock. Chen leaned on precedent, noting that Bybit held on after a $1.5 billion loss last year and saying that if Bybit could endure that, Bitget can endure a loss above $350 million. Earlier this year, North Korean hackers were allegedly behind a $280 million theft from Kelp and a $290 million theft from Drift, so the pipeline of large, attributed incidents shows no sign of narrowing.
Next Up
Bitget has promised a concrete withdrawal resumption plan by 4:00 UTC on September 26, and the market will judge the exchange on whether deposits, trading and redemptions return to normal without further surprises. The recovery effort now depends on how much of the $387.5 million can be frozen before it is mixed or bridged beyond reach, and on what Mandiant and SlowMist conclude about how the backend system was breached in the first place.
The larger question is whether the industry treats this as a Bitget problem or a systemic one. With North Korean-linked groups pushing past $1 billion stolen in 2026 and evidence of IT workers embedded inside companies, the defenses that matter are increasingly the boring ones: internal approval logic, employee vetting and monitoring that catches forged transaction data before it is signed. Until those improve, the next headline is a matter of when, not whether.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.