# Bitget’s $387.5 Million Hack: Unveiling the North Korean Connection

Canonical URL: https://www.teknalyze.com/tech-flash/bitget-hack-north-korean-connection/
Published: 2026-09-28
Updated: 2026-09-28
Author: Dana Morgan
Section: Tech Flash
Categories: Tech Flash, Technology
Primary topic: Bitget hack, cryptocurrency exchanges, North Korean cyber operations, digital asset security
Source: Tom’s Hardware
Source URL: https://www.tomshardware.com/tech-industry/cryptocurrency/north-korea-named-as-primary-suspect-in-usd387-million-bitget-crypto-hack-investigators-identify-ip-addresses-tied-to-vpn-infrastructure-previously-used-by-north-korean-hacker-groups-thieves-swapped-stablecoins-for-eth-in-minutes-to-dodge-freezes

## Summary

In a significant breach that has sent shockwaves through the cryptocurrency community, Bitget, a prominent crypto exchange, reported a theft of approximately $387.5 million from its hot and warm wallets on September 24, 2026. This incident marks the largest cryptocurrency hack of the year and underscores the persistent vulnerabilities within digital asset platforms.

## Key points

- Bitget reported a $387.5 million theft from its wallets on September 24, 2026.
- Attackers reportedly obtained internal credentials through a third-party security product.
- Bitget said its cold wallets and self-custody wallet were unaffected.
- Investigators suspect North Korean actors, citing network and on-chain indicators.
- Bitget says its protection fund is expected to cover customer balances.

## Why it matters

The reported Bitget theft illustrates how exchange losses can result from failures in internal authorization, even when private keys and cold wallets are untouched. Users need to know whether customer balances remain protected, while other exchanges may scrutinize third-party security products and withdrawal controls. Attribution to North Korean actors remains an investigative finding rather than a final determination.

## Article

In a significant breach that has sent shockwaves through the cryptocurrency community, Bitget, a prominent crypto exchange, reported a theft of approximately $387.5 million from its hot and warm wallets on September 24, 2026. This incident marks the largest cryptocurrency hack of the year and underscores the persistent vulnerabilities within digital asset platforms.

### The Attack Unfolded

Bitget’s security systems detected unauthorized transfers from its hot wallets at 18:31 UTC on September 24. Within an hour, on-chain investigators traced roughly $183 million in stablecoins, Ethereum, and other crypto assets moving out of wallets associated with the exchange. By the time Bitget publicly acknowledged the breach, total losses had escalated to $351.6 million, later revised to $387.5 million as additional affected assets were identified on networks like Zcash and TRON.

CEO Gracy Chen explained that the attackers exploited a vulnerability in a third-party security product, obtaining high-level internal credentials. They used these credentials to issue fraudulent withdrawal commands, bypassing the need to steal private keys. Notably, Bitget’s cold wallets and its self-custody product, Bitget Wallet, remained unaffected.

### Suspected North Korean Involvement

Investigations into the breach have pointed towards North Korean state-backed actors as the primary suspects. Chen noted that IP addresses and on-chain signatures associated with the attack closely resemble patterns previously linked to North Korean hacker groups. Blockchain analytics firm Elliptic also found connections between the stolen funds and addresses tied to earlier DPRK-attributed thefts, including the Bybit exploit.

This attribution aligns with previous incidents, such as the February 2025 Bybit hack, where North Korean hackers made off with approximately $1.4 billion. The FBI formally attributed that theft to North Korea, highlighting the regime’s ongoing efforts to fund its programs through illicit means.

### Implications for Exchange Security

The Bitget hack underscores the critical need for robust security measures within cryptocurrency exchanges. The attackers’ ability to manipulate internal authorization processes without accessing private keys highlights potential vulnerabilities in backend systems. This incident serves as a stark reminder for exchanges to continually assess and fortify their security infrastructures to prevent similar breaches.

In response to the attack, Bitget has engaged incident response firms Mandiant and SlowMist to assist with the investigation. The exchange has also launched a Recovery Bounty Program, offering rewards of up to 5% for funds successfully frozen or recovered. Additionally, Bitget’s User Protection Fund, which held more than $464 million at the time of the incident, is set to cover the full loss, ensuring that customer balances remain intact.

### Looking Ahead

As investigations continue, the cryptocurrency community remains vigilant, awaiting further developments. The Bitget hack serves as a critical case study in the ongoing battle against cyber threats in the digital asset space. It emphasizes the necessity for exchanges to implement comprehensive security protocols and for users to remain informed about potential risks.

The incident also raises broader questions about the geopolitical dimensions of cybercrime. With state-backed actors like North Korea increasingly targeting cryptocurrency platforms, the industry must consider the implications for international relations and the potential for regulatory responses.

In conclusion, the Bitget hack is a stark reminder of the vulnerabilities inherent in the cryptocurrency ecosystem. It calls for heightened security measures, increased transparency, and a collaborative approach to safeguarding digital assets against sophisticated cyber threats.

## Source

[Tom’s Hardware](https://www.tomshardware.com/tech-industry/cryptocurrency/north-korea-named-as-primary-suspect-in-usd387-million-bitget-crypto-hack-investigators-identify-ip-addresses-tied-to-vpn-infrastructure-previously-used-by-north-korean-hacker-groups-thieves-swapped-stablecoins-for-eth-in-minutes-to-dodge-freezes)
