North Korean Hackers Steal $351M from Bitget Exchange

The Heist That Wasn’t Supposed to Work

On September 24, 2026, at approximately 18:31 UTC, automated monitoring systems at cryptocurrency exchange Bitget flagged a series of unauthorized transfers draining funds from the platform’s hot and warm wallets. Within hours, roughly $351.6 million in digital assets — spanning ETH, XRP, BNB, AVAX, USDT, and USDC across seven blockchain networks — had been siphoned to attacker-controlled addresses. By the time Bitget suspended withdrawals and called in incident responders, the stolen funds were already being routed through a complex web of relay wallets and cross-chain bridges.

What makes this breach remarkable isn’t just the dollar figure. It’s that the attackers never stole a single private key. Instead, they compromised a backend system within Bitget’s wallet infrastructure and used it to forge transaction data, tricking the exchange’s own authorization process into approving the transfers. The technique mirrors an increasingly sophisticated playbook that blockchain analysts have linked directly to North Korean state-sponsored hackers — the same group behind the massive Bybit breach of 2025.

Inside the Backend Spoofing Attack

Traditional cryptocurrency exchange hacks typically involve stealing private keys — the cryptographic credentials that control access to blockchain wallets. The Bitget attack took a fundamentally different approach. Rather than going after the keys themselves, the attackers targeted the verification layer that sits between human operators and the blockchain.

According to Bitget’s post-incident disclosure, the intruders “compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out.” In practical terms, this means the authorization system displayed what appeared to be legitimate transfers while actually executing entirely different transactions underneath.

This is the same conceptual approach used in the February 2025 Bybit hack, where attackers manipulated the signing interface shown to cold wallet signers. The difference at Bitget was the target: rather than deceiving individual human signers reviewing cold storage transactions, the attackers compromised the automated approval pipeline for hot and warm wallets — the internet-connected systems used to process active trading and withdrawals.

Bitget has confirmed that private keys were never compromised and cold wallet reserves remained untouched, which limited the blast radius to the exchange’s liquidity layer. Still, the attackers managed to drain assets across Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain, Base, and TRON networks before detection.

Following the Money

Blockchain intelligence firms TRM Labs and Elliptic quickly began tracing the stolen funds. The distribution broke down to approximately $193 million on EVM-compatible chains, $158 million on the XRP Ledger, and $7 million in TRON-based tokens.

The laundering pattern followed a now-familiar playbook. Funds were first consolidated through relay wallets before being split into round-amount holdings — roughly 10,000 ETH or 20 million XRP per wallet — a technique designed to blend into normal large-holder activity. Smaller portions were converted to Bitcoin through decentralized bridges and swap services including THORChain, Across, Bridgers, Chainflip, and FixedFloat.

TRM Labs identified on-chain overlaps between the Bitget attacker wallets and addresses previously linked to North Korean operations, including the Bybit theft and the KelpDAO LayerZero bridge hack ($292 million). The firm traced these connections through “a laundering network TRM has not observed working with any other group.” Elliptic separately found connections between XRP from the Bitget exploit and ETH from a prior DPRK-attributed operation.

Stablecoin issuers moved quickly: Circle and Tether froze $339,100 in USDT and USDC linked to attacker addresses, though this represents a tiny fraction of the total haul.

North Korea’s Billion-Dollar Year

If the attribution holds — and multiple independent blockchain analytics firms consider it highly likely — the Bitget hack pushes North Korea’s 2026 cryptocurrency theft total past the $1 billion mark, making it the second-largest year on record behind 2025’s staggering haul driven primarily by the $1.5 billion Bybit breach.

The group behind these attacks, tracked as “TraderTraitor” by blockchain analysts, has evolved from targeting individual DeFi protocols to systematically compromising centralized exchange infrastructure. TRM Labs notes that North Korea now accounts for approximately three-quarters of all cryptocurrency thefts in 2026 — an extraordinary concentration that underscores the regime’s dependence on stolen crypto to fund its weapons programs.

Bitget CEO Gracy Chen stated the breach was “highly consistent with known patterns of North Korean hacker organizations.” The exchange enlisted Mandiant and SlowMist for a third-party investigation and launched a Recovery Bounty Program to mobilize community assistance in tracking the stolen funds.

The company has emphasized that its $464 million User Protection Fund should cover all customer losses, and that account balances remain accurate despite the wallet compromises. Phased withdrawal resumption began on September 28.

A Systemic Problem Getting Worse

The Bitget breach highlights a growing structural vulnerability in the cryptocurrency exchange industry. Backend spoofing attacks exploit a fundamental trust gap: the difference between what a verification system displays to operators and what it actually executes on-chain. As long as exchanges rely on single-layer authorization architectures for hot wallet operations, this attack surface remains exposed.

Security experts have pointed to MPC-based (multi-party computation) dual-signature architectures as a potential mitigation. Under this model, authorization is split across independent teams so that a single compromised system cannot move funds without a separate team’s independent risk review. However, implementing such architectures adds friction to withdrawal processing — exactly the kind of user experience tradeoff that competitive exchanges have historically resisted.

What to Watch and What to Do

For exchange operators, the lesson is urgent: if your hot wallet authorization pipeline relies on a single backend system to validate and execute transactions, you are running the same architecture that failed at Bitget and Bybit before it. Segregating the display layer from the execution layer, implementing out-of-band transaction verification, and adopting multi-party authorization for large transfers are no longer nice-to-haves.

For individual users and institutional investors, the takeaway is equally clear. Custodial risk hasn’t gone away — it has evolved. Checking whether your exchange maintains a published proof-of-reserves system and a protection fund is a reasonable starting point, but neither prevents a breach from happening in the first place. Consider limiting the amount of assets held on any single exchange, using hardware wallets for long-term storage, and monitoring exchange withdrawal policies for signs of irregularity.

Investigators will be watching the blockchain closely in coming weeks. North Korean laundering operations typically accelerate 30 to 60 days after a theft, as funds move through mixing services and are eventually converted to fiat. Whether law enforcement and blockchain analytics firms can freeze more of the stolen assets before that window closes will determine how much of the $351 million is ultimately recoverable.

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.