top of page
OutSystems-business-transformation-with-gen-ai-ad-300x600.jpg
OutSystems-business-transformation-with-gen-ai-ad-728x90.jpg
TechNewsHub_Strip_v1.jpg

LATEST NEWS

Bitget suspects North Korean hackers behind $352 million crypto heist

Marijan Hassan - Tech Journalist
49 minutes ago
2 min read

Cryptocurrency exchange Bitget has confirmed a major security breach resulting in the theft of approximately $351.6 million from its hot and warm wallet infrastructure. The attack, detected on September 24, 2026, forced the platform to temporarily freeze user withdrawals while security teams isolated the compromise.



During an emergency broadcast on social media platform X, Bitget Chief Executive Officer Gracy Chen revealed that preliminary forensic evidence points to North Korean state-sponsored cybercriminals, specifically the notorious Lazarus Group.


Sophisticated Backend System Compromise

Investigative findings indicate that the threat actors did not steal private keys or forge individual user withdrawal requests. Instead, the attackers directly penetrated Bitget's backend wallet management infrastructure, spoofing transaction details to bypass the platform's internal authorization mechanisms.


Key operational details of the breach include:

  • VPN and Infrastructure Footprints: Security analysts flagged IP addresses used during the intrusion that matched virtual private network patterns previously associated with Democratic People's Republic of Korea (DPRK) threat actor clusters.

  • Multi-Chain Asset Exfiltration: The attackers executed 19 unauthorized transactions across seven major blockchain networks, including Ethereum, XRP Ledger, Arbitrum, Avalanche, and BNB Smart Chain.

  • Impacted Holdings: The exfiltrated assets comprised Tether, USD Coin, Ether, Avalanche, and BNB, with XRP representing the single largest loss at over $157 million.


On-chain security researchers at SlowMist and Mandiant joined the investigation, noting that a portion of the stolen funds had already been routed through decentralized swaps to conceal tracking paths.


User Protection Reserve Fully Covers Financial Losses

Bitget emphasized that its cold storage infrastructure remained completely isolated and uncompromised throughout the incident. Moreover, executive leadership reassured platform users that customer account balances would be made whole.


Bitget’s dedicated User Protection Fund, which held over $464 million in reserve assets prior to the exploit, will cover the entire $351.6 million financial loss. The company maintains a self-funded reserve policy designed to keep protection assets above a $300 million floor.


Escalating Cyber Campaign Targeting Global Crypto Exchanges

The Bitget exploit represents one of the largest centralized exchange breaches of 2026, following the $1.5 billion hack of Bybit in early 2025, which U.S. federal authorities formally attributed to North Korean operatives.


International law enforcement agencies and blockchain foundations have begun freezing known wallet addresses linked to the stolen funds. While spot trading and deposit operations remain active, Bitget stated that withdrawal services will resume once comprehensive security audits confirm the platform's backend infrastructure is fully secured.

wasabi.png
Gamma_300x600.jpg
paypal.png
bottom of page