Skip to content
Cryptocurrencies

North Korea ‘Very Likely’ Behind $388 Million Hack of Crypto Exchange Bitget

The exchange says private keys were not stolen, a bitcoin-backed protection fund covers the loss, and withdrawals stay frozen while it investigates.
By

Reading time 4 minutes

Comments (3)

Crypto exchange Bitget says North Korea is very likely behind a theft of about $387.5 million that did not require anyone to steal the keys to the vault.

Security systems at the Seychelles-based platform flagged unauthorized transfers from some of its hot wallets at 18:31 UTC on Thursday, according to an official incident notice and a post from CEO Gracy Chen. The breach reached parts of Bitget’s hot and warm wallet layers. Cold wallets, which sit offline, were not hit. To be clear, the hack only affected Bitget Exchange. Bitget Wallet users were not affected.

Chen later said investigators had ruled out a private-key compromise. “The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” she wrote on X. In other words, the payouts looked legitimate to Bitget’s internal system. Bitget said the investigation is continuing with assistance from Mandiant and SlowMist.

Bitget first put the loss at $351.6 million and did not publish a token-by-token inventory. On-chain tracker Lookonchain listed 102.93 million XRP (about $157.48 million) as the largest slice, followed by 31,890 ETH (about $85.75 million), then USDT, USDC, USDT0, 3,000 XAUt of tokenized gold, BNB, AVAX, and TRX. Lookonchain also said the attacker had already swapped most of the EVM-chain proceeds into 67,982 ETH. Bitget later added Zcash and additional TRON balances that had been left out of its first official count and raised the official total to about $387.5 million. It said the revision is a fuller accounting of transfers during the incident, not more theft after the outflow was contained. Arkham Intelligence has tagged the hacker’s wallet on its blockchain intelligence platform.

Chen told customers their account balances remain accurate and that the entire loss sits inside Bitget’s User Protection Fund, which she valued at more than $464 million. Covering a $387.5 million loss would take most of that reserve. Bitget has said the fund is 5,500 bitcoin, so the dollar cushion moves with the bitcoin price until a payout is settled.

Withdrawals are paused pending a security review, but deposits and trading are still open. Bitget said it will announce a withdrawal plan by September 26 at 4:00 AM UTC.

Chen also launched a recovery bounty: 5% for voluntarily freezing attacker funds and 5% for voluntary recovery, plus a tracing dashboard and a path to submit leads through Bybit’s Lazarusbounty site. She said some blockchain foundations have already frozen attacker wallets.

Circle and Tether separately blacklisted one related address holding about $318,000 in USDC and USDT, a sliver next to the ether the thieves moved that no issuer can freeze. In the past, Circle has been criticized for its perceived lack of action in these sorts of situations.

North Korea Immediately Suspected

Chen linked the incident to North Korea during a live Q&A on X. “[We’ve] identified some IP addresses that match the VPN choices by a certain DPRK group,” she said. “The pattern looks very much like what the North Korean team did before.” She has not named the unit and added that Bitget does not currently believe the breach was an inside job.

Blockchain analytics firm Elliptic also assessed the Bitget attack as “highly likely” to be linked to North Korea. It pointed to on-chain ties between XRP taken from Bitget and ether from an earlier DPRK-attributed theft, and to Bitget proceeds touching addresses used to launder last year’s $1.4 billion Bybit heist.

MetaMask’s Taylor Monahan had already written that Bitget loot landed in an address that previously received Bybit stolen funds, and she named Lazarus as the actor. Lazarus is the label Western governments use for North Korea’s state-backed hacking crews. U.S. officials have described the group as operating under the regime’s military intelligence services and stealing crypto to help fund the government. Crypto scam investigator and Paradigm advisor ZachXBT also referred to this incident as “the Bitget exploit by DPRK,” though he said he had no plans to monitor it.

North Korean operators have been tied to the largest crypto thefts this year, including a six-month social-engineering campaign against Drift that ended with about $285 million gone in 12 minutes. In April, TRM Labs put the regime’s total take since 2017 above $6 billion and said North Korean agents accounted for 76% of stolen crypto value through that month. Elliptic said the Bitget incident is the largest single suspected North Korean crypto theft of 2026 and pushes those heists past $1 billion this year. Pyongyang has referred to their alleged crypto crimes as a “non-existent” cyber threat and dismissed the sources of those allegations as “U.S. government organs, reptile media organs and plot-breeding organizations.”

A Year of Crypto Hacks in the Time of Monsters

April was already the worst month on record for the number of crypto project hacks, with DefiLlama counting 29 incidents and Certik putting losses near $651 million, the largest monthly total since March 2022 if the February 2025 Bybit theft is set aside. DefiLlama now ranks the Bitget drain as the largest crypto hack of 2026, and CryptoSlate noted that adding Bitget’s initial $351.6 million figure already pushed September’s reported thefts above April and made this the costliest month of the year so far.

The crypto industry has also spent the year watching frontier AI models get better at finding critical bugs before they could be patched. OpenZeppelin co-founder Manuel Aráoz previously went as far as telling friends and family to exit DeFi, including names usually treated as blue chips, because “coding agents are superhuman at finding vulnerabilities.”

Even highly trusted, Bitcoin-focused systems have not been spared. Earlier this month, a bug in Blockstream’s Liquid Network software let attackers mint unbacked L-BTC and cash out roughly 4,000 bitcoin, then worth about $320 million, without stealing the federation’s keys. That episode followed a previous Coldcard hardware wallet vulnerability that had already been exploited for more than $100 million in bitcoin.

Explore more on these topics

Share this story

Sign up for our newsletters

Subscribe and interact with our community, get up to date with our customised Newsletters and much more.

Related Articles