BNB $774.82 -0.60%
XRP $1.57 +2.71%
ETH $2,690.36 -0.09%
BTC $83,955.28 -0.51%
BNB $774.82 -0.60%
XRP $1.57 +2.71%
ETH $2,690.36 -0.09%
BTC $83,955.28 -0.51%
BREAKING
Digital Wallet

Bitget’s $387 Million Hack Sparks North Korea Investigations Amid Security Flaws

Bitget Loses $387 Million in Hack as Lazarus Group Tactics Raise North Korea Fears
Bitget Loses $387 Million in Hack as Lazarus Group Tactics Raise North Korea Fears

Community Trust ScoreLikely Real

79%
Real
Likely Real14 votes
Updated 4 hours ago

Hackers hit Bitget hard. The exchange lost approximately $387.5 million in cryptocurrency on September 24, making it the largest crypto theft of the year by a significant margin. Law enforcement is now involved, and North Korea is being eyed as a possible culprit — though nothing’s confirmed yet.

Bitget’s security systems caught the breach at 18:31 UTC. Within an hour, internal teams had traced roughly $183 million in stablecoins, Ethereum, and other crypto assets moving out of the exchange’s hot wallets to addresses nobody recognized. Bitget went public with the incident hours later, initially reporting a loss of $351.6 million. That number kept climbing. By the time the dust settled, the total stood at $387.5 million — a figure that rattled the broader crypto market and put the exchange under intense scrutiny. CEO Gracy Chen addressed the situation directly through a livestream and a series of posts, walking through what happened and what Bitget planned to do about it.

The attack was surgical.

Advertisement

Chen said the hackers found a vulnerability inside Bitget’s backend wallet infrastructure. They didn’t crack private keys — cold wallets and hot wallets weren’t directly compromised in that sense. Instead, the attackers exploited a flaw that let them spoof transaction data, essentially tricking Bitget’s authorization system into signing off on fraudulent payouts. It’s a sophisticated method that bypasses the most obvious defenses and targets the logic layer instead. Harder to catch in real time, harder to stop once it’s moving.

Blockchain Trails and a $157 Million XRP Transfer

Blockchain analysts caught the first signs of trouble when a brand-new wallet dropped $19.67 million in USDT0 to buy 7,111 ETH at a premium. The purchases ran through decentralized exchanges — UniswapX and 1inch Fusion specifically — which offer fewer friction points than centralized platforms. More Bitget-linked wallets followed. Assets moved across five separate blockchains, landing in addresses the hacker controlled. The single largest transfer was 103 million XRP, worth around $157 million at the time. Spread across that many chains, the money gets messy to trace fast.

Chen moved quickly to halt further unauthorized transfers once the scale became clear. She also assured users that Bitget’s User Protection Fund — currently holding over $464 million — would cover the full loss. Trading kept running normally. Deposits weren’t interrupted. Withdrawals, though, got frozen as a precaution while the investigation got underway.

Not a small fund to tap. Bitget set it up in 2023 with an initial $300 million specifically to absorb situations like this one — hacks, thefts, scenarios where user funds end up at risk through no fault of the account holder. The fact that the fund exists and is large enough to cover the loss doesn’t make the breach less alarming, but it probably kept the panic from getting worse.

North Korea’s Lazarus Group in the Frame

Chen didn’t mince words about who she suspects. The hacking methods, she said, closely resemble techniques associated with North Korea’s Lazarus Group — a state-linked outfit that’s been tied to some of the biggest crypto heists in recent memory. She was also careful to add that the attacker’s identity is still unconfirmed and that no technical evidence has been publicly disclosed yet. So it’s a suspicion, not a conclusion.

She also mentioned something personal. The same group, she said, had previously targeted her directly, and that incident cost her $80,000 out of pocket. That detail adds a layer to this that goes beyond corporate damage control — it’s a pattern she’s seen up close.

Bitget brought in cybersecurity firms Mandiant and SlowMist to run a full forensic investigation. Both firms have deep experience in crypto-related breaches, and the collaboration is meant to pin down exactly how the attack unfolded and, if possible, who was behind it. A comprehensive incident report is coming, including a root-cause analysis once the technical teams finish patching and remediating the affected systems. Bitget said it’ll share findings as they become available.

Withdrawals were scheduled to resume the following day, with a formal plan to be announced separately.

The Lazarus Group angle isn’t new territory for the industry. State-sponsored hackers from North Korea have been linked to billions in crypto theft over the past several years, often using proceeds to fund weapons programs — a fact that’s drawn attention from the U.S. Treasury, the FBI, and international regulators. Whether Bitget’s breach fits that pattern remains unclear, but the method matches what analysts have documented in past Lazarus operations closely enough that it can’t be dismissed.

Bitget’s User Protection Fund covers the $387.5 million loss in full, per Chen.

Frequently Asked Questions

How much was stolen from Bitget in the September 2026 hack?

Hackers stole approximately $387.5 million in cryptocurrency from Bitget, making it the largest crypto hack of 2026 so far.

Will Bitget users lose money because of the hack?

Bitget CEO Gracy Chen said the exchange’s User Protection Fund, which holds over $464 million, will cover the entire loss, meaning user account balances should remain unaffected.

Who is suspected of hacking Bitget?

North Korea’s Lazarus Group is suspected based on similarities in hacking methods, though Chen said the attacker’s identity is still unconfirmed and no technical evidence has been publicly disclosed.

Why It Matters

The significant loss incurred by Bitget highlights ongoing vulnerabilities within cryptocurrency exchanges, which continue to be prime targets for sophisticated hacking groups, such as the suspected North Korean Lazarus Group. This incident not only raises concerns over the security of digital assets but also amplifies fears regarding state-sponsored cybercrime, potentially impacting investor confidence and regulatory scrutiny in the broader crypto market. As exchanges grapple with the fallout, the incident may lead to calls for enhanced security measures and more robust regulatory frameworks to protect user assets.

Community Trust IndexModerate Confidence
79%
Real
Real79%21%Fake
14 community signals

Sakamoto Nashi

Nashi Sakamoto is a dedicated crypto journalist from the Virgin Islands who brings expert analysis on Bitcoin, Ethereum, DeFi protocols, and the broader digital asset ecosystem to The Currency Analytics.

Advertisement

Related Stories