Bitget Hack Losses Climb to $387.5 Million After Backend Compromise
Cryptocurrency exchange Bitget has revised the total losses from its September 24, 2026 security breach upward to $387.5 million, after initially disclosing $351.6 million stolen from its hot and warm wallets. Bitget CEO Gracy Chen said the higher figure reflects additional affected assets identified on the Zcash and TRON networks that were not captured in the exchange's first damage assessment. Chen has publicly pointed to North Korea-linked actors as the suspected culprits, citing IP addresses tied to VPN infrastructure previously used by DPRK-affiliated hacking crews, and independent blockchain investigators — including MetaMask's Taylor Monahan — have traced stolen funds to wallet addresses previously associated with the Bybit hack, a pattern consistent with the Lazarus Group.
Incident at a Glance
| Attribute | Value |
|---|---|
| Victim | Bitget (cryptocurrency exchange) |
| Initial estimate | $351.6 million (disclosed September 25, 2026) |
| Revised/current estimate | $387.5 million (added Zcash and TRON exposure) |
| Detection time | 18:31 UTC, September 24, 2026 |
| Wallets affected | Hot and warm wallets; cold wallets reported unaffected |
| Suspected actor | North Korea-linked group; on-chain links point to the Lazarus Group |
| Attack method | Backend compromise and spoofed transaction data, not private-key theft |
| Assets stolen | XRP, ETH, USDT, USDC, Tether Gold, BNB, AVAX, and others |
| Chains involved | Ethereum, XRP Ledger, Arbitrum, Optimism, BNB Smart Chain, Avalanche, Base, plus Zcash and TRON |
| Response | Withdrawals suspended; deposits and trading continued |
| Forensic partners | Mandiant, SlowMist |
| Compensation | Bitget's User Protection Fund (5,500 BTC, over $464 million) plus $1 billion-plus in proprietary capital |
How It Worked
Two Reports, One Evolving Figure
Bitget's initial disclosure, reported first by The Hacker News, put the loss at $351.6 million based on the exchange's early review of unauthorized transfers flagged at 18:31 UTC on September 24, 2026. Roughly five hours later, The Record reported that Chen had raised the figure to $387 million during a livestream, attributing the jump to previously uncounted assets on Zcash and TRON. Later reporting settled on $387.5 million as the more precise revised total. CosmicBytez Labs is treating $351.6 million as the initial estimate and $387.5 million as the current, higher figure — consistent with how fast-moving breach disclosures typically evolve as forensic scope expands.
Not a Private-Key Theft
Chen has repeatedly emphasized that this was not a conventional wallet-draining hack. According to her account, attackers did not obtain the private keys controlling Bitget's cold, hot, or warm wallets. Instead, they compromised a backend system inside Bitget's wallet infrastructure and used it to spoof transaction data, tricking the exchange's own authorization process into approving transfers that appeared routine. Chen has compared the mechanism to slipping forged withdrawal slips past a bank's teller window — the vault keys never left the building, but the back-office paperwork process was manipulated to push transfers through.
Multi-Chain, Multi-Asset Exfiltration
The stolen funds spanned a wide range of assets and chains. Reported breakdowns include roughly $153 million in XRP, $66.2 million in ETH, $34.8 million in USDT, $12.9 million in USDC, and $12.8 million in Tether Gold, with additional exposure on Arbitrum, Optimism, BNB Smart Chain, Avalanche, and Base. The revised total added assets on Zcash and TRON that were identified after the initial disclosure. Attackers reportedly moved a portion of the proceeds — on the order of $183 million — into Ether shortly after the theft, a common laundering step to consolidate value before further obfuscation.
North Korea and Lazarus Group Attribution
Chen said investigators identified IP addresses matching VPN services previously used by a North Korean state-linked hacking group, and that the attack's overall pattern — backend compromise, spoofed authorization, rapid multi-chain dispersal — resembles prior DPRK-attributed operations. Separately, blockchain investigator Taylor Monahan flagged that a portion of the Bitget loot landed in a wallet address that had previously received funds stolen in the Bybit hack, a link she used to name the Lazarus Group specifically. Bitget has not yet published a completed forensic report formally attributing the breach to a specific actor or state.
Response and Recovery
Bitget suspended withdrawals as a precaution while deposits and trading continued uninterrupted, and engaged Mandiant and SlowMist for third-party forensic investigation. The exchange said it has contacted the foundations of all affected blockchains, some of which have confirmed freezing attacker-linked wallet addresses. Bitget also launched a recovery bounty program offering 5% of recovered funds to parties that voluntarily freeze attacker-controlled wallets, plus an additional 5% for funds ultimately recovered.
Impact Assessment
| Impact Area | Description |
|---|---|
| Direct financial loss | $387.5 million (revised up from an initial $351.6 million estimate) |
| Customer funds | Bitget says balances remain accurate and will be made whole via its User Protection Fund |
| Operational | Withdrawals suspended as a precaution; deposits and trading unaffected |
| Reputational | Largest confirmed centralized-exchange crypto theft of 2026 to date, surpassing Liquid Network's $319 million breach earlier this month |
| Industry-wide | Reinforces that backend/authorization systems, not just private-key custody, are a viable path to exchange-scale theft |
| Attribution risk | North Korea/Lazarus linkage raises sanctions exposure for any platform or service that touches the stolen funds |
Recommendations
For Exchange Operators
- Treat backend systems that generate or authorize wallet transactions as critical attack surface on par with private-key custody — this breach never touched a key yet still moved hundreds of millions.
- Enforce independent, out-of-band verification between wallet tiers so a compromised hot-wallet-facing backend cannot silently authorize warm- or cold-wallet movement.
- Maintain a well-funded, transparent user protection reserve and commit to frequent public updates during an active incident — Bitget's continued deposits/trading and running disclosures limited operational fallout.
For Security and Threat Intelligence Teams
- Track the wallet addresses and laundering paths (including the Bybit-linked address flagged by Taylor Monahan) for reuse across other suspected DPRK operations.
- Coordinate early with blockchain foundations capable of freezing flagged addresses; several already froze attacker-linked wallets in this case.
- Expect loss figures in fast-moving breach disclosures to change materially in the first 24-48 hours as forensic scope expands across additional chains — build that into incident communications planning rather than treating the first number as final.
For Bitget Users and Crypto Holders Generally
- Verify account balances only through official Bitget channels and treat unsolicited "recovery" or "compensation" messages referencing this hack as likely phishing.
- Prefer self-custody or hardware wallets for significant long-term holdings rather than concentrating balances on any single exchange.
- Watch for Bitget's promised full forensic report before drawing final conclusions on root cause or attribution.
Key Takeaways
- Bitget's loss estimate rose from an initial $351.6 million to a revised $387.5 million after additional Zcash and TRON exposure was identified — CosmicBytez Labs is using $387.5 million as the current headline figure.
- The attack did not involve private-key theft; attackers compromised a backend system and spoofed transaction data to trigger Bitget's own transfer-authorization process.
- Stolen assets spanned XRP, ETH, USDT, USDC, Tether Gold, and more, across at least nine blockchains.
- North Korea is the suspected actor based on IP/VPN evidence cited by CEO Gracy Chen, with independent researcher Taylor Monahan linking proceeds to a wallet previously tied to the Lazarus Group and the Bybit heist.
- Bitget's User Protection Fund (5,500 BTC, over $464 million) plus more than $1 billion in proprietary capital is intended to cover all customer losses; withdrawals were suspended only as a precaution.
- This is the largest confirmed centralized-exchange crypto theft of 2026 so far, extending a run of major breaches that includes Liquid Network ($319 million) and the Coldcard hardware-wallet attack ($116 million).