Crypto

Bitget Attributes $352M Crypto Hack to North Korean Attack

3 min read · September 25, 2026
Hero illustration for the article “Bitget Attributes $352M Crypto Hack to North Korean Attack”

Bitget Links $352 Million Crypto Theft to North Korean Hackers

Bitget, a leading cryptocurrency exchange, has publicly connected a recent $351.6 million digital asset theft to North Korean cyberattackers. This attribution comes after the company identified internet protocol addresses linked to VPN services previously used by North Korean hacking groups. The breach was detected on a Thursday afternoon in the United States, affecting multiple wallet types and several blockchain networks.

CEO Gracy Chen revealed these details during a livestream on X, emphasizing the seriousness of the attack and its resemblance to prior North Korean cyber operations. The revelation marks a significant development in the ongoing battle against state-sponsored cybercrime in the crypto space.

Scope and Method of the Breach

The unauthorized transfers originated from Bitget’s hot and warm wallets, involving 19 separate transactions, while the exchange’s cold wallets remained secure. The stolen assets spanned multiple cryptocurrencies, including ether, XRP, USDT, USDC, Avalanche, and BNB, across the Ethereum, XRP Ledger, Avalanche, BNB Smart Chain, and Arbitrum networks.

Initial on-chain assessments estimated the outflows at approximately $183 million; however, Bitget clarified that those estimates did not account for all affected blockchains, leading to the updated figure of $351.6 million. The breach involved a critical backend wallet system, which was exploited to fake transfer information and bypass authorization protocols.

Security Response and Ongoing Investigation

Bitget’s security team quickly contained the breach, preventing further losses by suspending withdrawals while maintaining normal deposit and trading functions. Importantly, the company ruled out private key compromise, indicating the attacker exploited internal system vulnerabilities rather than direct cryptographic key theft.

The technical investigation into the specific intrusion method remains active. Chen indicated that withdrawal services could resume within hours or days but are not expected to remain suspended for weeks. Meanwhile, the company is reinforcing its systems to prevent recurrence of similar incidents.

Financial Impact and Customer Protection

Despite the substantial loss, Bitget assures customers that all balances remain accurate and that the stolen funds are fully covered by its User Protection Fund, which reportedly holds over $464 million. This fund is designed to shield users from losses due to security breaches and maintain client confidence during crises.

The exchange’s swift public disclosure and transparent communication aim to mitigate reputational damage and reassure users amid heightened concerns about crypto exchange vulnerabilities. The incident underscores the importance of robust security infrastructures in safeguarding digital assets.

Industry Collaboration and Wider Cybersecurity Implications

Bybit CEO Ben Zhou confirmed that his company is ready to assist Bitget in the investigation and recovery efforts. Bybit had previously received help after suffering a $1.5 billion hack in February 2025, illustrating the cooperative spirit among crypto exchanges facing common threats.

Bybit is updating its LazarusBounty platform, a tool designed to trace stolen funds and disrupt hacker cash-outs. This collaboration highlights the growing emphasis on inter-exchange cooperation and technological innovation to combat cybercrime, especially threats linked to nation-state actors like North Korea.

Takeaway: Bitget’s attribution of a $352 million crypto theft to North Korean hackers highlights persistent cybersecurity risks in the digital asset industry and the critical need for robust defenses and cross-industry cooperation.