Backend Compromise, Not a Stolen Key
Cryptocurrency exchange Bitget disclosed that suspected North Korean threat actors stole $351.6 million from its hot and warm wallets, with Bitget's security systems flagging unauthorized transfers at 18:31 UTC on September 24, 2026. According to Bitget CEO Gracy Chen, the root cause was not a stolen private key: attackers compromised a backend system in the exchange's wallet infrastructure and spoofed the transaction data shown to its internal approval process, tricking it into authorizing transfers it should have rejected. Bitget says private keys were never exposed and its cold wallets were untouched.
The initial $351.6 million figure has since been revised upward as blockchain-tracing firms continued following the funds — to roughly $387.5 million, once assets moved on Zcash and TRON (absent from the first count) were included, with some later on-chain tracing citing a total as high as ~$390 million.
Incident at a Glance
| Attribute | Detail |
|---|---|
| Initial disclosed loss | $351.6 million |
| Revised loss estimate | ~$387.5 million (some tracing cites ~$390 million) |
| Detection time | 18:31 UTC, September 24, 2026 |
| Root cause | Backend compromise — spoofed transaction data tricked internal transfer approval |
| Private keys | Not stolen, per Bitget |
| Cold wallets | Untouched |
| Chains/assets affected | ETH, XRP, BNB, AVAX, USDT, USDC across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain, Base; Zcash and TRON added in the revised total |
| Largest single-chain loss | XRP, approximately $158 million (TRM Labs) |
The Attribution Picture
No government has formally attributed the Bitget hack to North Korea. Bitget itself points to IP addresses tied to VPN infrastructure previously associated with DPRK-linked operations, plus similarities in attack pattern to prior North Korean campaigns. Blockchain forensics firm TRM Labs identified on-chain wallet overlaps between this incident's laundering infrastructure and funds from the Bybit hack ($1.5 billion, 2025) and the AFX Bridge hack — both linked to the TraderTraitor cluster associated with North Korea's Lazarus Group ecosystem. TRM Labs has stopped short of definitively attributing this specific exploit to North Korea, however.
Notably, independent blockchain investigator ZachXBT, who moved quickly to trace the Bybit theft, has publicly said he has "no current plans to monitor" the Bitget case — a contrast some in the crypto-security community have flagged given the scale involved.
Bitget's Response
- Withdrawals were suspended immediately following detection, then resumed in phases starting September 28 at 8:00 UTC, beginning with Bitcoin.
- Bitget engaged Mandiant and SlowMist for third-party investigation; the exploited vulnerability has reportedly been identified and patched.
- Circle and Tether froze approximately $318,000 in USDC/USDT tied to one exploiter-associated address — a small fraction of total losses. Ether itself cannot be frozen by an issuer, leaving tens of thousands of ETH beyond that kind of intervention.
- Bitget launched a Recovery Bounty program offering 5% for funds frozen and 5% for funds recovered, and says its $464 million-plus User Protection Fund is sufficient to cover the full loss to affected users.
How This Compares to 2026's Other North Korea-Linked Heist
The Bitget incident draws immediate comparison to the Drift Protocol hack from earlier in 2026, in which roughly $285-286 million was stolen from the Solana-based platform following a six-month, in-person social-engineering operation attributed to the DPRK-linked cluster UNC4736 (also tracked as AppleJeus). Bitget's loss is larger in raw dollar terms and used a different method — direct backend/infrastructure compromise rather than prolonged social engineering of employees.
If North Korean involvement in the Bitget hack is eventually confirmed, 2026 would become the second-largest year on record for North Korean cryptocurrency theft, at roughly $1.04 billion, trailing only 2025's $1.68 billion.