Cryptocurrency exchange Bitget reported that suspected North Korean threat actors have taken $351.6 million from its hot and warm wallets in a breach detected on September 24, 2026. The company's security systems identified unauthorized transfers at 18:31 UTC involving a limited set of hot wallets, while cold storage and the vast majority of platform assets remained untouched. Customer account balances stayed accurate, and deposits plus trading continued without disruption, though withdrawals were paused temporarily pending a comprehensive security review.
The stolen assets included ETH, XRP, BNB, AVAX, USDT, and USDC across seven blockchain networks: Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. On-chain tracing later revised the total to roughly $390.06 million transferred to attacker-controlled addresses across multiple networks. Blockchain analytics firm Elliptic observed connections between XRP from the Bitget exploit and ETH from a previous North Korea-attributed exploit, as well as links between stolen Bitget funds and addresses used to launder past North Korea-attributed exploits, including the 2025 Bybit theft. Circle and Tether have frozen stablecoins worth $339,100 tied to the hack, according to a real-time fund tracing dashboard. If confirmed as North Korean activity, 2026 would become the second-largest year on record for North Korean crypto theft at $1.04 billion, trailing only 2025's $1.68 billion.
Bitget CEO Gracy Chen said the attack method in this incident closely matches known patterns of North Korean hacker organizations based on IP behavior patterns and on-chain analysis. The attacker compromised a critical backend system within the wallet infrastructure, used it to spoof transaction data, and triggered the authorization process to move funds out, Chen explained. The company has contacted foundations of all affected chains, and some have confirmed freezing hacker wallet addresses. TRM Labs uncovered multiple overlaps with wallets used to launder previous North Korean hacks, including Bybit and AFX Bridge, pointing to the involvement of the TraderTraitor group. SentinelOne had attributed TraderTraitor to an attack targeting an India-based IT services company about a week earlier; the group is best known for the theft of $1.5 billion from Bybit and $292 million from KelpDAO's LayerZero bridge.
The breach exposes how attackers infiltrated a critical backend system to manipulate transaction data and bypass authorization controls without triggering immediate alarms. Bitget enlisted Google-owned Mandiant and SlowMist for a third-party investigation, though the specific method of system intrusion remains under active investigation. Elliptic noted that shared laundering infrastructure between incidents is a recurring feature in the laundering of North Korea-attributed hacks, with launderers prioritizing speed over operational discipline. The company launched a Recovery Bounty Program to mobilize exchanges, blockchain projects, security researchers, investigators, and the wider on-chain community to assist with freezing and recovering affected assets.
Bitget announced on September 26, 2026 that it would resume withdrawals in orderly phases starting September 28 at 8 a.m. UTC, adding the vulnerability involved in the incident has been identified and addressed. The incident remains contained, and no further unauthorized transfers are possible, Bitget stated. User funds are unaffected throughout this process, and trading plus deposits continue to operate. Ari Redbord, Global Head of Policy at TRM Labs, said North Korea keeps stealing from this ecosystem at alarming speed and scale, adding the industry must harden cyber controls and also go after these actors offensively using every national security authority available. The breach underscores the persistent challenge of securing centralized wallet infrastructure against state-sponsored adversaries, particularly when those adversaries operate sophisticated laundering networks that span multiple exploits. Exchanges now face mounting pressure to balance operational speed with the kind of layered security architectures that can detect and halt spoofed transaction flows before billions more vanish into adversarial coffers.

