Suspected North Korean Hackers Steal $351.6M from Crypto Exchange Bitget
Cryptocurrency exchange Bitget has confirmed that suspected North Korean threat actors stole $351.6 million from its hot and warm wallets. The company said its security systems detected unauthorised transfers at 18:31 UTC on 24 September 2026, but stressed that cold wallets and the majority of platform assets remain secure. Customer balances, deposits, and trading continue as normal, though withdrawals have been temporarily suspended while a full security review takes place.
Bitget has not yet disclosed exactly how the attackers got in, but has brought in Mandiant and SlowMist to investigate. According to CEO Gracy Chen, the stolen assets include ETH, XRP, BNB, AVAX, USDT, and USDC across multiple blockchain networks. The attacker reportedly compromised a critical backend system within the wallet infrastructure, used it to spoof transaction data, and triggered the authorisation process to move funds out. Bitget says no further unauthorised transfers are possible, and some blockchain foundations have already frozen the hacker's wallet addresses. Chen noted that the attack patterns are highly consistent with known North Korean hacking operations.
This incident follows a similar attribution last week, where the North Korea-linked TraderTraitor group was tied to an attack on an India-based IT services company. TraderTraitor has previously been linked to the theft of $1.5 billion from Bybit and $292 million from a LayerZero bridge, underscoring a pattern of large-scale, state-linked cryptocurrency theft.