
Bitget reports up to $387.5 million stolen in hack linked to North Korea
Seychelles-based cryptocurrency exchange Bitget suspended customer withdrawals after attackers drained up to $387.5 million from its hot and warm wallets, with internal investigations pointing to North Korean hacker groups.
Breach detection and initial response
Seychelles-based cryptocurrency exchange Bitget detected unauthorized transfers from its network at 18:31 UTC on Thursday, 24 September 2026. The platform, which serves more than 120 million registered users and ranks as the fifth largest exchange by spot trading volume according to CoinMarketCap, moved quickly to freeze customer withdrawals. Company officials initially calculated the stolen sum at approximately $351.6 million before revising the total figure to $387.5 million after identifying additional TRON and Zcash transfers. The breach affected portions of Bitget's hot and warm wallet systems, while its offline cold storage and the separate Bitget Wallet app remained untouched. Deposits and spot trading remained open across the platform.
Mechanics of the backend intrusion
Investigators determined that the intrusion bypassed typical private-key theft by compromising internal infrastructure. According to chief executive Gracy Chen, the perpetrator gained access to a critical backend system in Bitget's wallet architecture, using it to spoof transaction records and trigger automated authorization protocols across 19 separate transfers.
The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out.
Blockchain analytics service Lookonchain tracked the outflow, revealing that 102.93 million XRP (valued at roughly $157.48 million) formed the largest portion of the initial loot, alongside 31,890 ether valued at approximately $85.75 million. The stolen assets also included Tether, USD Coin, Avalanche, BNB, and 3,000 XAUt tokens of tokenized gold. The attacker subsequently converted the majority of the proceeds on EVM chains into 67,982 ether, with Arkham Intelligence tagging the recipient addresses.
User protection and recovery measures
Bitget maintained that all customer account balances remained fully intact and that all user assets were safe. The company announced that the financial deficit would be absorbed by its User Protection Fund, an emergency reserve holding 5,500 bitcoin with an estimated value exceeding $464 million. Bitget engaged external cybersecurity firms Mandiant and SlowMist to conduct independent forensic examinations of the breached infrastructure.
Withdrawals remain temporarily suspended as a security precaution, not because of any shortfall in funds.
To accelerate fund retrieval, the exchange offered a dual 5% recovery bounty for voluntarily freezing or returning stolen assets, while setting a deadline of 4:00 AM UTC on 26 September 2026 to outline its withdrawal resumption schedule.
- Bitget security systems flag unauthorized transfers from hot and warm wallets.
- Bitget pauses withdrawals and launches investigation with Mandiant and SlowMist.
- Scheduled deadline for Bitget to announce its customer withdrawal resumption plan.
Industry impact and North Korean attribution
Preliminary forensic findings linked the breach to cyber units associated with North Korea. Chen noted that network investigators traced connecting IP addresses to VPN services previously used by North Korean state-sponsored threat groups. The incident represents the largest single cryptocurrency theft recorded in 2026, surpassing an April attack on KelpDAO that took $292 million and an early September theft of $319 million from Liquid Network.
- KelpDAO (April 2026)
- 292 $M
- Liquid Network (Sept 2026)
- 319 $M
- Bitget (Sept 2026)
- 387.5 $M
According to TRM Labs data, attackers had stolen $1.73 billion across 333 digital asset security incidents during 2026 prior to the Bitget breach, with North Korean collectives responsible for approximately 75% of total stolen value year to date. The scale of the intrusion follows previous large-scale digital heists, including the February 2025 theft of $1.5 billion in ether from exchange Bybit. North Korea has consistently denied carrying out cyberattacks or cryptocurrency heists.


