NEWS

Bitget Loses $351.6M in Suspected North Korean Backend Compromise

Bitget's hot wallets lost $351.6M — since revised toward $387.5M — after attackers spoofed its backend to approve fraudulent transfers.

Dylan H.

News Desk

September 27, 2026
4 min read
Bitget Loses $351.6M in Suspected North Korean Backend Compromise

Backend Compromise, Not a Stolen Key

Cryptocurrency exchange Bitget disclosed that suspected North Korean threat actors stole $351.6 million from its hot and warm wallets, with Bitget's security systems flagging unauthorized transfers at 18:31 UTC on September 24, 2026. According to Bitget CEO Gracy Chen, the root cause was not a stolen private key: attackers compromised a backend system in the exchange's wallet infrastructure and spoofed the transaction data shown to its internal approval process, tricking it into authorizing transfers it should have rejected. Bitget says private keys were never exposed and its cold wallets were untouched.

The initial $351.6 million figure has since been revised upward as blockchain-tracing firms continued following the funds — to roughly $387.5 million, once assets moved on Zcash and TRON (absent from the first count) were included, with some later on-chain tracing citing a total as high as ~$390 million.


Incident at a Glance

AttributeDetail
Initial disclosed loss$351.6 million
Revised loss estimate~$387.5 million (some tracing cites ~$390 million)
Detection time18:31 UTC, September 24, 2026
Root causeBackend compromise — spoofed transaction data tricked internal transfer approval
Private keysNot stolen, per Bitget
Cold walletsUntouched
Chains/assets affectedETH, XRP, BNB, AVAX, USDT, USDC across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain, Base; Zcash and TRON added in the revised total
Largest single-chain lossXRP, approximately $158 million (TRM Labs)

The Attribution Picture

No government has formally attributed the Bitget hack to North Korea. Bitget itself points to IP addresses tied to VPN infrastructure previously associated with DPRK-linked operations, plus similarities in attack pattern to prior North Korean campaigns. Blockchain forensics firm TRM Labs identified on-chain wallet overlaps between this incident's laundering infrastructure and funds from the Bybit hack ($1.5 billion, 2025) and the AFX Bridge hack — both linked to the TraderTraitor cluster associated with North Korea's Lazarus Group ecosystem. TRM Labs has stopped short of definitively attributing this specific exploit to North Korea, however.

Notably, independent blockchain investigator ZachXBT, who moved quickly to trace the Bybit theft, has publicly said he has "no current plans to monitor" the Bitget case — a contrast some in the crypto-security community have flagged given the scale involved.


Bitget's Response

  • Withdrawals were suspended immediately following detection, then resumed in phases starting September 28 at 8:00 UTC, beginning with Bitcoin.
  • Bitget engaged Mandiant and SlowMist for third-party investigation; the exploited vulnerability has reportedly been identified and patched.
  • Circle and Tether froze approximately $318,000 in USDC/USDT tied to one exploiter-associated address — a small fraction of total losses. Ether itself cannot be frozen by an issuer, leaving tens of thousands of ETH beyond that kind of intervention.
  • Bitget launched a Recovery Bounty program offering 5% for funds frozen and 5% for funds recovered, and says its $464 million-plus User Protection Fund is sufficient to cover the full loss to affected users.

How This Compares to 2026's Other North Korea-Linked Heist

The Bitget incident draws immediate comparison to the Drift Protocol hack from earlier in 2026, in which roughly $285-286 million was stolen from the Solana-based platform following a six-month, in-person social-engineering operation attributed to the DPRK-linked cluster UNC4736 (also tracked as AppleJeus). Bitget's loss is larger in raw dollar terms and used a different method — direct backend/infrastructure compromise rather than prolonged social engineering of employees.

If North Korean involvement in the Bitget hack is eventually confirmed, 2026 would become the second-largest year on record for North Korean cryptocurrency theft, at roughly $1.04 billion, trailing only 2025's $1.68 billion.


Sources