securityaffairs.com 25 Sept 2026, 18:02 UTC

Bitget Says North Korea Linked Hackers Stole $351.6 Million

Bitget Says North Korea Linked Hackers Stole $351.6 Million
CyberSIXT Evidence Panel Source marked as original reporting

CRYPTOCURRENCY exchange Bitget says suspected North Korea-linked threat actors stole $351.6 million from a limited number of hot and warm wallets. Its security systems detected unauthorised transfers at 18:31 UTC on 24 September 2026, prompting the exchange to suspend withdrawals temporarily. Bitget said customer balances, cold wallets and most platform assets remain secure, while deposits and trading continue normally. Its separate, self-custodial Bitget Wallet was not affected, according to the company.

Bitget chief executive Gracy Chen said the breach involved ETH, XRP, BNB, AVAX, USDT and USDC across several blockchains. The attacker allegedly compromised a critical backend wallet system, spoofed transaction data and bypassed the authorisation process to move funds. Mandiant and SlowMist are investigating, and Bitget said it had contacted the foundations of all affected chains; some reportedly confirmed that hacker wallet addresses had been frozen.

Bitget has attributed the activity to North Korea-linked groups based on IP behaviour patterns and on-chain analysis, but this remains the company’s assessment rather than confirmed attribution. The exchange said its User Protection Fund covers the impact of the incident.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline