North Korea suspected in $387 million Bitget crypto hack

Exchange CEO cites hallmarks of state-sponsored attackers; user funds protected by $464 million reserve

By LineZotpaper
Published
Updated
Read Time3 min
Sources3 outlets
North Korean state-sponsored hackers are the prime suspects in a $387.5 million theft from crypto exchange Bitget, the company's CEO said, marking the largest crypto hack of 2026. The attack exploited a backend wallet system on September 24, temporarily freezing withdrawals, but Bitget's User Protection Fund will cover the full loss.

Bitget CEO Gracy Chen announced during an X livestream on the evening of the September 24 hack that the attack bore the hallmarks of North Korean state-sponsored threat actors. She cited suspicious IP addresses tied to VPN infrastructure previously used by North Korean hacker groups.

Bitget detected abnormal transfers from some hot wallets on Thursday afternoon Eastern time. The hackers exploited a backend wallet system that processes wallet transactions, forging transfer approvals that tricked the system into authorizing the fraudulent transactions. Chen confirmed that cold wallets and private keys remained safe and uncompromised.

The stolen assets include Ether, XRP, USDT, USDC, Avalanche, and BNB across the Ethereum, XRP Ledger, Avalanche, BSC, and Arbitrum networks. Early independent on-chain analysis initially put the total stolen value at $170 million to $183 million, before Bitget announced an initial official value of $351.6 million. Comprehensive audits revised the final official value to $387.5 million.

Bitget temporarily froze user withdrawals, while deposits and trading remained functional. The company announced that its over $464 million User Protection Fund would cover the full loss. It says it has fixed the backend vulnerability and is rolling out a staggered withdrawal schedule starting Monday, September 28, to manage network traffic and ensure complete infrastructure security.

After the attack, the hackers quickly converted USDT, USDC, and tokenized gold (XAUt) into ETH on decentralized exchanges within minutes of the theft to circumvent on-chain blacklisting or freezing of the stablecoins. Native layer-1 assets like XRP, ETH, BNB, and TRX, which cannot be frozen or reversed, were quickly fragmented and distributed across dozens of new attacker-controlled wallets. Bitget launched a recovery-bounty program offering rewards of up to 5% for funds successfully frozen or recovered.

The incident is the latest in a series of hacks in the crypto industry. Earlier this month, attackers drained $320 million in Bitcoin from the Liquid Network, emptying nearly 95% of its federation wallet. In April, crypto platform Drift lost $270 million in a hack. Many hacks have been linked to state actors, with North Korea leading the pack. In February 2025, the FBI identified North Korean hackers as the perpetrators behind the biggest crypto hack in history, stealing over $1.5 billion from Bybit.

§

Analysis

Why This Matters

  • The hack is the largest crypto theft of 2026, raising concerns about security vulnerabilities in exchange backend systems.
  • North Korean state-sponsored hacking continues to be a major threat to the crypto industry, with billions stolen over recent years.
  • Bitget's use of its User Protection Fund to cover losses sets a precedent for exchange accountability, but may not fully restore user trust.

Background

Crypto exchanges have long been targets for hackers, with North Korean groups such as the Lazarus Group frequently implicated in major thefts. State-sponsored hackers often use sophisticated techniques to exploit hot wallet vulnerabilities and quickly launder stolen funds through decentralized exchanges. The February 2025 Bybit hack, where $1.5 billion was stolen, remains the largest such incident. Bitget is a Seychelles-based crypto exchange with a substantial user base and a publicly disclosed User Protection Fund.

Key Perspectives

Bitget: The exchange has taken responsibility by covering the full loss from its User Protection Fund, fixing the vulnerability, and implementing a staggered withdrawal schedule to ensure security. CEO Gracy Chen has been transparent about the suspected North Korean involvement. Users: Affected users may be reassured by the fund covering losses, but the temporary freeze on withdrawals and the scale of the hack could erode confidence in the platform's security. Critics: Some industry observers may question why hot wallets remain vulnerable to such exploits despite numerous past incidents. The rapid conversion and distribution of stolen assets highlight ongoing challenges in tracing and recovering funds.

What to Watch

  • Whether Bitget's staggered withdrawal schedule proceeds smoothly and restores normal operations.
  • The success of the recovery-bounty program in freezing or recovering any of the stolen funds.
  • Potential regulatory responses or increased scrutiny of exchange security practices from global financial authorities.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.