CRYPTOCURRENCY exchange Bitget says suspected North Korea-linked threat actors stole $351.6 million from a limited number of hot and warm wallets. Its security systems detected unauthorised transfers at 18:31 UTC on 24 September 2026, prompting the exchange to suspend withdrawals temporarily. Bitget said customer balances, cold wallets and most platform assets remain secure, while deposits and trading continue normally. Its separate, self-custodial Bitget Wallet was not affected, according to the company.
Bitget chief executive Gracy Chen said the breach involved ETH, XRP, BNB, AVAX, USDT and USDC across several blockchains. The attacker allegedly compromised a critical backend wallet system, spoofed transaction data and bypassed the authorisation process to move funds. Mandiant and SlowMist are investigating, and Bitget said it had contacted the foundations of all affected chains; some reportedly confirmed that hacker wallet addresses had been frozen.
Bitget has attributed the activity to North Korea-linked groups based on IP behaviour patterns and on-chain analysis, but this remains the company’s assessment rather than confirmed attribution. The exchange said its User Protection Fund covers the impact of the incident.