North Korean hackers suspected in $351 million theft from Bitget exchange

Bitget, one of the world's largest cryptocurrency exchanges, disclosed Thursday that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets — the biggest known cryptocurrency theft of 2026.
The attack occurred on September 24 at 18:31 UTC. According to Bitget CEO Gracy Chen, the attackers "compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out." Cold storage remained untouched.
The stolen assets span six cryptocurrencies — ETH, XRP, BNB, AVAX, USDT, and USDC — drained across seven blockchain networks including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Smart Chain, and Base.
Bitget suspended all withdrawals shortly after detecting the breach and began working with law enforcement, on-chain security firms, and cybersecurity company Mandiant. The exchange says its $464 million user protection fund covers the full losses and has committed to making affected users whole.
North Korea's fingerprint
Bitget attributes the attack to North Korean state-sponsored hackers based on IP behavior patterns and on-chain tracing. "The attack method in this incident is highly consistent with known patterns of North Korean hacker organizations," CEO Chen said in a statement reported by TechCrunch.
Blockchain intelligence firm TRM Labs estimates that North Korea is responsible for roughly three-quarters of all cryptocurrency thefts in 2026 to date. Groups like Lazarus have systematically targeted exchanges and DeFi protocols to fund Pyongyang's weapons programs; UN investigators estimate cumulative crypto theft of around $3 billion since 2017.
The year's biggest heist
The $351.6 million figure eclipses a $340 million hack earlier in September, in which the attacker returned all but $47 million. It also surpasses the $305 million DMM Bitcoin hack that made headlines in 2024.
The scale and technique — backend compromise, transaction spoofing, multi-chain drain — mirrors previous North Korean operations. What's different this time is the speed: Bitget's security systems flagged the breach within hours, and the company suspended withdrawals before the attackers could convert and launder all the funds.
As of publication, withdrawals remain suspended while Bitget works to trace the stolen assets. The company has not given a specific reopening timeline.
Originally reported by TechCrunch. Read the original article for additional details.
View original source