Crypto

Bitget Blames North Korean Hackers for $352M Crypto Theft

4 min read · September 25, 2026
Hero illustration for the article “Bitget Blames North Korean Hackers for $352M Crypto Theft”

Bitget Links $351.6 Million Crypto Hack to North Korean Actors

Crypto exchange Bitget has attributed a massive $351.6 million cryptocurrency security breach to hackers linked to North Korea, based on early findings in an ongoing investigation. CEO Gracy Chen revealed that internet protocol addresses connected to VPN services previously associated with North Korean hacking groups were detected during the probe. This attribution follows the detection of unauthorized transactions on September 24, 2026, involving multiple digital assets across several blockchain networks.

The incident is notable for its scale and the sophistication of the attack, which targeted Bitget’s hot and warm wallets but spared its cold wallets. The hack has prompted the exchange to suspend withdrawals temporarily while continuing deposits and trading operations, assuring customers of full coverage by its substantial User Protection Fund.

Details of the Attack and Assets Affected

The breach involved 19 unauthorized transfers from Bitget’s wallet infrastructure on the afternoon of September 24, 2026, U.S. Eastern Time. Affected cryptocurrencies included ether (ETH), XRP, USDT, USDC, Avalanche (AVAX), and Binance Coin (BNB), spanning the Ethereum, XRP Ledger, Avalanche, BNB Smart Chain, and Arbitrum networks. Initial on-chain analyses underestimated the total loss at around $183 million, but Bitget’s internal assessment raised the figure to $351.6 million after accounting for all impacted blockchains.

Investigators found that the hacker compromised a critical backend wallet system, which was then used to falsify transaction data and activate Bitget’s authorization-signing process. Importantly, the breach did not involve the compromise of private keys, a fact confirmed by CEO Chen, which suggests the attacker exploited a vulnerability within Bitget’s infrastructure rather than gaining control of the fundamental cryptographic credentials.

Response and Recovery Efforts

Following the discovery of the hack, Bitget’s security team contained the intrusion and halted further unauthorized transfers. Withdrawals remain suspended as technical teams work to repair and reinforce the compromised systems. Meanwhile, deposits and trading have continued without disruption, maintaining service continuity for users.

Chen indicated that the timeline for restoring withdrawals is uncertain but anticipated to be within hours or days rather than weeks. This cautious optimism reflects the complex nature of the technical fixes required to secure the backend wallet systems and to prevent recurrence.

Financial Impact and Customer Protection

Despite the significant value stolen, Bitget guarantees that the loss will not affect customer balances. The exchange’s User Protection Fund, reportedly holding more than $464 million, will fully cover the stolen assets. This fund acts as an internal insurance mechanism to shield users from financial damage due to security breaches.

The assurance of full coverage is critical for maintaining user trust amid a climate of increasing crypto-related cyberattacks. It also highlights Bitget’s preparedness in allocating substantial reserves for crisis management, an approach increasingly adopted by large exchanges to mitigate reputational and financial risks.

Industry Collaboration and Wider Implications

In a show of solidarity, Bybit CEO Ben Zhou announced readiness to support Bitget’s recovery efforts. Bybit previously received assistance from Bitget after suffering a $1.5 billion hack in February 2025. To aid in tracing the stolen funds, Bybit is enhancing its LazarusBounty platform, which targets assets linked to North Korean cybercrime groups.

This cooperation underscores growing industry efforts to counteract state-sponsored cybercriminal activities and improve security intelligence sharing. The attribution to North Korean actors aligns with broader concerns about the regime’s use of cyberattacks to generate revenue amid international sanctions and economic isolation.

Takeaway: Bitget’s swift response and financial safeguards limit customer impact from the $351.6 million breach linked to North Korean hackers, while industry collaboration intensifies to combat such threats.