Daily Beirut

Tech & Science

Bitget Suffers $387.5M Crypto Heist, Blames North Korea

Bitget confirms a $387.5 million theft from hot wallets, with CEO Gracy Chen attributing the breach to North Korean actors.

··4 min read
Bitget Suffers $387.5M Crypto Heist, Blames North Korea
Share

A massive security breach at Seychelles-based crypto exchange Bitget resulted in the loss of approximately $387.5 million, an incident the platform’s leadership has attributed to North Korean state-sponsored actors. The theft occurred without the compromise of private keys, challenging traditional assumptions about wallet security vulnerabilities.

Breach Mechanics and Initial Response

Security systems detected unauthorized transfers from hot wallets at 18:31 UTC on Thursday, September 24, 2026. CEO Gracy Chen stated that emergency protocols were activated immediately upon detection. The attack targeted both hot and warm wallet layers, while cold wallets remained offline and unaffected. Chen clarified that the incident was isolated to Bitget Exchange, leaving Bitget Wallet users untouched.

Investigations ruled out private-key theft. Instead, attackers compromised a critical backend system within the wallet infrastructure. This access allowed them to spoof transaction data, triggering the authorization process to move funds. To internal systems, the payouts appeared legitimate. Bitget is continuing its investigation with support from cybersecurity firms Mandiant and SlowMist.

Financial Impact and Asset Breakdown

Initial estimates placed the loss at $351.6 million, but this figure was later revised upward after accounting for Zcash and additional TRON balances omitted from the first report. On-chain tracker Lookonchain identified XRP as the largest component of the stolen assets, totaling 102.93 million tokens valued at roughly $157.48 million. Other significant losses included 31,890 ETH (about $85.75 million), USDT, USDC, USDT0, tokenized gold (XAUt), BNB, AVAX, and TRX.

Lookonchain reported that the attacker converted most proceeds from EVM chains into 67,982 ETH. Arkham Intelligence tagged the hacker’s wallet on its blockchain intelligence platform. Stablecoin issuers Circle and Tether blacklisted one related address holding approximately $318,000 in USDC and USDT. However, this action covers only a fraction of the total loss, particularly regarding ether which cannot be frozen by issuers.

Attribution to North Korean Actors

During a live Q&A on X, Chen linked the incident to North Korea, citing IP addresses matching VPN choices used by a specific DPRK group. She noted the pattern resembled previous attacks by North Korean teams. Blockchain analytics firm Elliptic assessed the attack as “highly likely” connected to North Korea, pointing to on-chain ties between the stolen XRP and ether from earlier DPRK-attributed thefts. Elliptic also observed that Bitget proceeds touched addresses used to launder funds from last year’s $1.4 billion Bybit heist.

MetaMask’s Taylor Monahan identified that Bitget loot landed in an address previously receiving stolen Bybit funds, naming Lazarus as the actor. Western governments use the label Lazarus for North Korea’s state-backed hacking crews, which U.S. officials say operate under military intelligence services to fund the regime. Paradigm advisor ZachXBT referred to the event as “the Bitget exploit by DPRK.”

Recovery Efforts and User Protection

Chen assured customers that account balances remain accurate, stating the entire loss is covered by Bitget’s User Protection Fund, valued at more than $464 million. This reserve consists of 5,500 bitcoin, meaning its dollar value fluctuates with market prices until settlement. Withdrawals are paused pending a security review, though deposits and trading remain open. A withdrawal plan is scheduled for announcement by 4:00 AM UTC on September 26.

Bitget launched a recovery bounty offering 5% for voluntarily freezing attacker funds and 5% for voluntary recovery. A tracing dashboard and submission path via Bybit’s Lazarusbounty site were established. Some blockchain foundations have already frozen attacker wallets. Elliptic described this as the largest single suspected North Korean crypto theft of 2026, pushing total DPRK-linked heists past $1 billion this year.

Broader Context of Crypto Security

North Korean operators have been tied to major crypto thefts in 2026, including a social-engineering campaign against Drift that resulted in about $285 million lost in 12 minutes. TRM Labs estimated the regime’s total take since 2017 exceeds $6 billion, with North Korean agents responsible for 76% of stolen crypto value through April. Pyongyang has dismissed these allegations as a “non-existent” cyber threat, criticizing sources as “U.S. government organs, reptile media organs and plot-breeding organizations.”

The industry continues to face evolving threats, including AI-driven vulnerability discovery. OpenZeppelin co-founder Manuel Aráoz previously advised exiting DeFi due to coding agents’ superior ability to find bugs. Earlier this month, a bug in Blockstream’s Liquid Network software allowed attackers to mint unbacked L-BTC and cash out roughly 4,000 bitcoin, worth about $320 million at the time. DefiLlama now ranks the Bitget drain as the largest crypto hack of 2026, surpassing April’s record-breaking month for incident volume.

Add Daily Beirut to your Google News feed to get the latest first.
Share