Bitget Hack Pushes Suspected North Korean Crypto Theft Above $1 Billion in 2026

Image: Bbc
Main Takeaway
Bitget says a wallet breach drained about $351.6 million, pushing suspected North Korean cryptocurrency theft above $1 billion this year.
Jump to Key PointsSummary
The Bitget breach and immediate response
Bitget says attackers drained approximately $351.6 million in digital assets from parts of its hot and warm wallet infrastructure on Sept. 25, making the exchange breach one of the largest cryptocurrency thefts of 2026. The exchange detected unauthorized transfers across multiple blockchains and said its cold wallets remained secure. Bitget also paused withdrawals while investigating the incident, according to Reuters AI and Finance.yahoo.
The company’s user-protection fund holds more than $464 million and is intended to cover the loss, according to Pluang. Chief Executive Gracy Chen said user funds remain protected and described the incident as an infrastructure attack rather than a compromise of the exchange’s offline reserves. The size of the reported loss varies by account: Bloomberg AI cited about $357 million, while Fortune AI put the figure above $387 million, reflecting continuing efforts to identify and value the stolen assets.
How attackers bypassed wallet controls
The suspected attackers compromised a backend wallet system and spoofed transaction data so fraudulent transfers appeared legitimate. The breach allowed them to initiate withdrawals from hot and warm wallets without obtaining Bitget’s underlying private keys, according to Thehackernews and Cryptorank. That distinction matters because it points to a failure in transaction authorization and operational controls, rather than a direct theft of offline signing credentials.
Hot wallets remain connected to trading operations, while warm wallets have limited online exposure. Their compromise can still produce a large loss when backend systems approve transfers across several networks. Finance.yahoo reported that attackers created or used a newly created wallet to drain assets in under an hour, while Bitget said its cold-wallet reserves were untouched. The episode places renewed pressure on exchanges to isolate transaction systems, verify withdrawal requests independently and limit automated permissions.
Why North Korea is suspected
Bitget’s preliminary assessment points to North Korean-linked hackers, based on attack patterns, infrastructure indicators and associated IP addresses. The attribution remains an exchange assessment rather than a public government determination, but it aligns with a long record of large cryptocurrency thefts attributed to Pyongyang. CNBC reported that Chen identified North Korea as the leading suspect, while Bloomberg AI cited Elliptic Enterprises in estimating that the Bitget theft pushed North Korea’s cryptocurrency haul above $1 billion in 2026.
The FBI has attributed the $1.5 billion Bybit theft in February 2025 to North Korea’s TraderTraitor activity. The BBC reported that hackers linked to the Lazarus Group converted at least $300 million from that haul into difficult-to-recover funds. Those cases show why attribution affects more than public messaging: investigators track laundering routes, exchanges screen wallets and governments assess whether stolen digital assets are financing the North Korean regime.
A larger pattern of escalating theft
The Bitget incident lands after North Korean crypto theft reached record levels. Chainalysis estimated that North Korean hackers stole $2.02 billion in cryptocurrency during 2025, a 51% increase from the previous year, bringing the all-time total to $6.75 billion. NBCnews reported that the increase came even as the number of attacks fell, indicating that individual operations are producing larger payouts.
Earlier in 2026, North Korean groups were linked to about $577 million in theft from 2 attacks, according to TRM Labs. Those incidents accounted for 76% of global crypto hack losses through April, with the Drift Protocol attack alone valued at $285 million. The Bitget breach therefore extends a pattern of concentrated, high-value attacks against exchanges and decentralized finance platforms. Chainalysis has tied prior operations to social engineering, impersonation and the placement of North Korean IT workers inside technology companies.
What exchanges and users face next
Bitget’s response will focus on tracing assets, restoring normal withdrawals and determining how backend authorization was bypassed. The exchange’s protection fund gives it a direct mechanism for absorbing the reported loss, but reimbursement does not remove the security questions raised by a transfer system that treated forged requests as valid. Investigators and blockchain analytics firms will watch recipient wallets for rapid swaps, layering and movement through services that obscure transaction histories.
For users, the immediate issue is access to withdrawals and confidence in exchange custody. For other platforms, the breach reinforces the need for separate approval paths, strict limits on hot-wallet balances and continuous review of administrative systems. Bybit’s earlier $1.5 billion theft showed that laundering can begin quickly, while the Bitget case shows that a backend compromise can threaten substantial reserves even when cold storage remains intact.
The stakes for crypto security
The Bitget hack raises the suspected North Korean crypto theft total above $1 billion for 2026 and adds another major exchange to a growing list of targets. Its reported $351.6 million loss is smaller than the Bybit heist but large enough to rank among the year’s defining cybercrime incidents. The attack also demonstrates how security failures can occur between custody and execution, where software determines whether a transfer request is genuine.
The next phase will depend on Bitget’s forensic findings, law-enforcement attribution and the movement of the stolen assets. A confirmed North Korean link would add to evidence that Pyongyang’s operators are increasing the value of individual attacks while using varied methods across centralized exchanges and decentralized protocols. The episode leaves exchanges with a clear operational task: reduce the amount held online, separate approval systems and treat backend transaction data as a high-value attack surface.
Key Points
Bitget reported a $351.6 million wallet breach tied preliminarily to suspected North Korean hackers.
North Korean-linked thefts surpassed $1 billion in 2026 after the Bitget attack, according to Elliptic.
Bitget said attackers targeted hot and warm wallets while cold-storage reserves remained secure.
Attackers allegedly spoofed transaction data after compromising Bitget’s backend wallet infrastructure.
Bitget’s protection fund, valued above $464 million, is designated to cover the reported loss.
Questions Answered
Bitget reported approximately $351.6 million in stolen digital assets. Other estimates ranged from about $357 million to more than $387 million as investigators continued assessing the affected wallets and assets.
Bitget says preliminary evidence points to North Korean-linked hackers. The assessment is based on attack patterns and infrastructure indicators, while the investigation and public attribution remain ongoing.
Bitget said its cold wallets remained secure. The reported theft affected hot and warm wallets connected to operational systems and involved a backend authorization compromise.
The Bitget attackers allegedly compromised a backend wallet system and spoofed transaction data so fraudulent withdrawals appeared legitimate. Investigators said the attackers did not obtain Bitget’s private keys.
Bitget said its user-protection fund, holding more than $464 million, will cover the reported loss. The exchange paused withdrawals during its investigation and must restore services while tracing the stolen assets.
Source Reliability
50% of sources are highly trusted · Avg reliability: 76
Go deeper with Organic Intel
Simple AI systems for your life, work, and business. Each one includes copyable prompts, guides, and downloadable resources.
Explore Systems