Crypto exchange Bitget has confirmed one of the largest security breaches in the industry's history, with attackers making off with approximately $388 million in digital assets across multiple blockchain networks — and preliminary evidence pointing toward North Korea's state-linked hackers as the likely culprits [1][2].
What Happened — and How
Bitget's security systems first flagged unauthorized transfers leaving its hot wallets at 18:31 UTC on September 24, 2026 [1]. Within an hour, on-chain investigators had already traced roughly $183 million in stablecoins, Ethereum, and other assets flowing out of wallets associated with the exchange [1]. By the time Bitget issued a public statement, the confirmed loss stood at $351.6 million — a figure the exchange subsequently revised upward twice, settling at approximately $388 million after identifying additional affected assets on the Zcash and TRON networks [2].
Critically, the attackers did not steal private keys or forge user withdrawal requests. Instead, they penetrated a backend system within Bitget's wallet infrastructure and manipulated transaction data, tricking the exchange's own authorization process into approving transfers that appeared routine [1]. CEO Gracy Chen described it plainly: the attackers forged the paperwork rather than cracking the vault — the digital equivalent of slipping a convincing fake withdrawal slip past a verification system that checks the form, not the identity behind it [1].
Scale and Scope of the Breach
The breach touched wallets across at least five blockchain networks, including Ethereum Virtual Machine-compatible chains, the XRP Ledger, Zcash, and TRON [2]. Affected assets spanned a wide range: XRP, Ether, Tether's USDt, USDC, USDT0, Zcash, XAUt, BNB, AVAX, and TRX [2].
The single largest component of the haul was approximately 103 million XRP, valued at around $157 million at the time of the theft [1]. Blockchain researchers also flagged early signs of the breach independently: pseudonymous analyst DCF GOD identified a freshly created wallet that spent $19.67 million in USDT0 to purchase 7,111 ETH within six minutes, paying roughly 5% above market price through decentralized exchanges UniswapX and 1inch Fusion [1].
While the breach ranks among the largest in crypto history, it remains well below the approximately $1.5 billion stolen from rival exchange Bybit in February 2025 [2].
North Korea in the Frame
Chen has been careful to frame the attribution as preliminary rather than confirmed, but her language has been pointed. "We've identified some IP addresses that match the VPN choices by a certain DPRK group," she said during a live Q&A on X, adding that "the pattern looks very much like what the North Korean team did before" [1][2]. Security investigators working with Bitget also flagged similarities between this breach and prior North Korean attacks [2].
Chen further disclosed that she has personally been targeted by the same suspected group, losing approximately $80,000 from a personal wallet unconnected to Bitget [1].
Bitget has engaged Mandiant and blockchain security firm SlowMist to conduct forensic analysis, with Chen noting that thorough investigation takes more than 24 hours and that further findings would be shared as they become available [1]. The exchange has also launched a bounty program aimed at helping freeze or recover stolen assets, and Chen confirmed during the Q&A that some funds had already been recovered — though she did not specify an amount [2].
It bears noting that North Korean attribution in crypto hacks, while frequently accurate in retrospect, is treated as analysis based on behavioral and technical indicators until formally confirmed by law enforcement.
North Korea's Growing Crypto Footprint
The suspected involvement of North Korean hackers fits a well-established pattern. The country's Lazarus Group — also tracked under the codename TraderTraitor — has been blamed for the industry's most damaging heists [1]. The FBI formally attributed the Bybit hack to North Korean actors weeks after that February 2025 incident [1]. Blockchain analytics firm Chainalysis has estimated North Korea's total crypto theft in 2025 at more than $2 billion, with separate reporting putting the figure at approximately $2.02 billion [1][2].
The Bitget breach, if confirmed as North Korean work, would add meaningfully to that running total and reinforce concerns that state-sponsored actors have developed sophisticated techniques specifically designed to exploit exchange infrastructure without needing direct access to private keys.
Customer Funds and Exchange Operations
Chen said the unauthorized outflow has been stopped and no further transfers are possible [1]. Bitget's User Protection Fund — which currently holds more than $464 million, up from $300 million when it was established in 2023 — will cover the full loss, leaving customer account balances intact [1]. Deposits and trading continued uninterrupted throughout the incident; only withdrawals were suspended as a precaution [1]. The exchange said it would announce a plan for resuming withdrawals once its investigation reaches an appropriate milestone [1].
What to Watch Next
Several threads remain open. Bitget has promised a full incident report including root-cause analysis once system remediation is complete [1]. The forensic investigation by Mandiant and SlowMist is ongoing, and any technical evidence made public could either solidify or complicate the North Korea attribution [1]. Law enforcement is now involved, and the bounty program may yield additional asset recovery [2]. Separately, the departure of SEC Commissioner Hester Peirce — who announced she will leave her post on October 2 after roughly eight years and serving as director of the agency's Crypto Task Force — removes a prominent pro-clarity voice from U.S. crypto regulation at a moment when exchange security is again under intense scrutiny [2].


