Bitget’s $387.5 Million Hack: What Happened, Why North Korea Is a Suspect, and What It Means for Exchange Security

Bitget confirmed on September 25, 2026, that a security breach initially estimated at roughly $183 million had grown to $387.5 million in stolen assets — making it the largest cryptocurrency exchange hack of 2026. Unlike most exchange breaches, the attackers didn’t steal private keys or forge withdrawal requests; according to CEO Gracy Chen, they instead penetrated backend wallet infrastructure and spoofed transaction data to trick the exchange’s own systems into approving payouts that looked routine. On-chain evidence points toward North Korean state-linked hackers, echoing tactics used in last year’s record-breaking $1.4 billion Bybit theft. Here’s the full timeline, how the attack worked, and what it means for exchange security more broadly.

The Hack in Numbers

DetailFigure
Initial detected loss (Sept 24, 2026)~$183 million
Revised total loss (Sept 25, 2026)$387.5 million
XRP stolen~103 million tokens (~$157 million)
USDT0 (cross-chain Tether) converted to ETH$19.67 million
ETH purchased above market via UniswapX/1inch Fusion7,111 ETH (~5% premium paid)
Blockchains affectedAt least 5
Bitget’s User Protection Fund~$464 million (covers full losses)
CEO’s personal loss (same attacker group, per Chen)~$80,000
Comparable prior hack: Bybit (Feb 2025)$1.4 billion

Timeline of the Attack

  • 18:31 UTC, Sept 24: Unauthorized transfers first detected moving out of Bitget’s hot wallets
  • ~19:31 UTC, Sept 24: Initial internal loss tally reached approximately $183 million
  • Hours later, Sept 24: Bitget publicly confirmed the breach and froze outflows
  • Sept 25, 2026: After accounting for previously unrecognized Zcash and TRON holdings involved in the breach, the confirmed total was revised up to $387.5 million
  • Sept 26, 2026: Withdrawals scheduled to resume under new security procedures

How the Attack Actually Worked

What makes this breach notable from a security-research perspective is the method. Bitget CEO Gracy Chen was explicit about what did not happen: “They did not forge user withdrawal requests, nor did they obtain our private keys of the cold wallet.” No user accounts were compromised, and no customer withdrawal instructions were faked. Instead, the attackers found a way into Bitget’s backend wallet infrastructure and manipulated the transaction data feeding into the exchange’s own internal authorization systems — effectively tricking Bitget’s automated approval process into treating fraudulent outbound transfers as routine, pre-approved payouts.

Security researchers have compared this to forging paperwork rather than breaking into a vault: the attacker didn’t need to crack any cryptographic key or bypass multi-signature cold storage protections directly, because the internal system itself was fooled into believing the transfers were legitimate. Once transfers were approved, the attackers moved quickly to convert stolen assets across multiple blockchains and, notably, purchased 7,111 ETH through decentralized exchange aggregators UniswapX and 1inch Fusion at roughly a 5% premium above market price — a choice that suggests the attackers prioritized speed and execution certainty over cost efficiency, consistent with an actor trying to launder and disperse funds before they could be frozen or tracked.

Why North Korea Is the Leading Suspect

Bitget’s CEO cited several specific indicators pointing toward North Korean state-linked involvement, without claiming definitive proof. IP addresses used during the attack reportedly matched VPN patterns previously associated with North Korean hacking operations, and on-chain fund-movement signatures — the specific sequence and pattern of how stolen assets were split, bridged, and converted — aligned with techniques security researchers have tied to North Korean state-linked groups in prior incidents. Chen stated plainly: “the pattern looks very much like what the North Korean team did before,” while explicitly cautioning that the attacker’s identity remains unconfirmed and that no technical evidence has been publicly released to substantiate the attribution.

That caveat is important for readers to keep in mind: attribution in cryptocurrency hacks is notoriously difficult to prove conclusively in the days immediately following an incident, and exchanges have both a genuine security interest and, at times, a reputational incentive to point toward a well-known external threat actor rather than an internal vulnerability. Bitget has said a full incident report and root-cause analysis will follow once system remediation is complete, alongside forensic investigations from Mandiant and SlowMist — two established blockchain security and incident-response firms — which should provide more conclusive evidence than the preliminary indicators cited so far.

The Lazarus Group Track Record

If the North Korea attribution holds up, it would extend a pattern that has made state-linked hacking group Lazarus (also tracked under the name TraderTraitor by Western security agencies) the single most consequential threat actor in cryptocurrency security. The group’s most notorious recent operation was the February 2025 Bybit hack, in which attackers made off with approximately $1.4 billion — later formally attributed to North Korea by the FBI — making it the largest cryptocurrency theft in history at the time. Security researchers estimate North Korean state-linked actors stole more than $2 billion in cryptocurrency across various operations in 2025 alone, funds that United Nations investigators and Western intelligence agencies have repeatedly linked to financing the country’s weapons programs.

The Bitget incident, at $387.5 million, is smaller in absolute terms than the Bybit theft but is still the largest single crypto exchange hack recorded so far in 2026, underscoring that despite years of warnings, increased regulatory scrutiny, and substantial security investment across the industry, state-sponsored actors continue to find and exploit gaps in exchange infrastructure — this time not through classic private-key theft but through a more sophisticated manipulation of internal authorization logic.

Bitget’s Response and User Protection

To Bitget’s credit, the exchange’s response followed several practices that security experts generally consider best practice after a breach is detected. Outflows were halted almost immediately once unauthorized transfers were identified, preventing further losses beyond the initial breach window. Trading and deposits continued operating normally throughout the incident, and user account balances were not altered or reduced — the losses were absorbed by Bitget’s infrastructure rather than passed on to customers. Most significantly, Bitget confirmed its User Protection Fund, reported at approximately $464 million, will fully cover the $387.5 million in losses, meaning affected users should be made whole without needing to wait for stolen funds to be recovered or frozen by exchanges and law enforcement.

This is a meaningfully different outcome than several prior exchange collapses, where user funds were effectively lost when an exchange lacked sufficient reserves or insurance to cover a breach. Whether an exchange maintains a dedicated, sufficiently capitalized protection fund — and is transparent about its size and terms before a crisis occurs — has become one of the clearest practical differentiators between exchanges that survive a major security incident with user trust intact and those that don’t.

What This Means for Exchange Security Industry-Wide

The Bitget breach offers several lessons that extend well beyond one exchange’s incident report:

  • Cold wallet security isn’t the only attack surface: Bitget’s cold wallet private keys were never compromised, yet attackers still moved hundreds of millions of dollars by manipulating the backend systems that authorize transfers — a reminder that internal process security matters as much as key custody
  • Detection speed matters more than perfect prevention: Bitget detected and froze outflows within roughly an hour of the first unauthorized transfer, which likely limited what could have been an even larger loss
  • Insurance and protection funds are now a baseline expectation: users and institutions evaluating exchanges increasingly treat the existence and size of a proven protection fund as a core due-diligence factor, not a nice-to-have
  • Attribution takes time and shouldn’t be treated as settled: preliminary indicators pointing to North Korea are consistent with past patterns but are not yet confirmed by independent forensic reporting
  • State-sponsored crypto theft remains a persistent, escalating threat: with over $2 billion attributed to North Korean actors in 2025 alone, exchanges of every size should assume they are potential targets regardless of their existing security posture

How This Ranks Among Crypto’s Biggest Exchange Hacks

Placing the Bitget breach in historical context helps illustrate both how far exchange security has come and how much further it still has to go. The industry’s largest hacks have consistently involved either sophisticated state-sponsored actors or catastrophic internal control failures, and the dollar figures involved have generally scaled up alongside the total value locked in the crypto ecosystem itself.

IncidentDateAmount StolenSuspected/Confirmed Actor
BybitFebruary 2025$1.4 billionNorth Korea (Lazarus Group) — FBI confirmed
BitgetSeptember 2026$387.5 millionNorth Korea suspected (unconfirmed)
FTX (fraud/mismanagement, not a hack)November 2022~$8 billion in customer fundsInternal fraud, not external attack
Mt. Gox2014~$470 million at the time (~850,000 BTC)Unconfirmed, long-running investigation

What stands out about the Bitget incident relative to this history is the response time and resolution path. Where Mt. Gox took years to resolve creditor claims and FTX’s collapse wiped out customer funds entirely due to commingled assets and outright fraud, Bitget froze outflows within roughly an hour, kept trading and deposits running normally throughout, and immediately committed a fully funded protection reserve to cover 100% of the loss. That doesn’t make the underlying security failure any less serious — a $387.5 million theft through manipulated backend authorization logic is a significant lapse regardless of how well it was handled afterward — but it does mark a meaningful evolution in how well-capitalized exchanges are now expected to manage a crisis once one occurs, compared to the industry’s earlier, far messier precedents.

How Users Can Protect Themselves After an Exchange Hack

For everyday users, exchange-level breaches like this one are largely outside their direct control, but a few practices reduce individual exposure regardless of which platform experiences an incident. Withdrawing large balances to self-custodied wallets during periods of extended market inactivity limits how much capital sits exposed to any single exchange’s infrastructure at once. Enabling withdrawal address whitelisting and hardware-based two-factor authentication protects individual accounts even if broader platform-level security is compromised, since neither of those user-side protections would have been affected by the type of backend authorization exploit Bitget experienced. And diversifying which exchanges hold active trading capital — rather than concentrating everything on one platform — limits the maximum realistic loss from any single incident, a basic risk-management principle that applies to exchange counterparty risk just as it does to any other form of concentration risk.

What to Watch Next

  • Bitget’s full incident report and root-cause analysis, expected once Mandiant and SlowMist complete their forensic investigations
  • Formal attribution confirmation or denial from independent security researchers or government agencies regarding North Korean involvement
  • Whether stolen funds get frozen or recovered — exchanges and law enforcement have had mixed success intercepting stolen crypto before it’s fully laundered through mixers and cross-chain bridges
  • Withdrawal resumption on Sept 26 and whether the new security procedures introduce friction for legitimate users
  • Whether other exchanges disclose similar attempted intrusions, which would suggest this was part of a broader coordinated campaign rather than an isolated incident targeting Bitget specifically

Why Exchange Security Practices Matter When Choosing Where to Trade

Incidents like this are a useful reminder that the fee structure and asset selection users typically compare across exchanges are only part of the picture — security architecture, proof of reserves, and the existence of a real, sufficiently capitalized user protection fund matter just as much, if not more, especially during periods of heightened market volatility when exchange infrastructure tends to come under the most strain. KCEX maintains dedicated cold storage protocols and a transparent reserve structure alongside its 0% maker and taker fee spot trading model, and incidents like the Bitget breach are a useful prompt for any trader to periodically review how their exchange of choice handles custody, incident response, and user fund protection before, not after, a crisis occurs.

FAQ: The Bitget $387.5 Million Hack

How much was stolen in the Bitget hack?
The confirmed total is $387.5 million, revised up from an initial estimate of approximately $183 million after Bitget accounted for previously unrecognized Zcash and TRON holdings involved in the breach.

Were user funds or private keys stolen?
No. Bitget’s CEO stated that attackers did not forge user withdrawal requests or obtain cold wallet private keys. Instead, they manipulated backend transaction data to trick the exchange’s internal authorization system into approving fraudulent transfers.

Will affected users be reimbursed?
Yes. Bitget confirmed its User Protection Fund, valued at approximately $464 million, will fully cover the $387.5 million in losses, and customer account balances have not been reduced.

Was North Korea confirmed to be behind the attack?
Not conclusively. Bitget’s CEO cited IP address patterns and on-chain signatures consistent with prior North Korean state-linked hacking operations, but explicitly noted the attacker’s identity remains unconfirmed pending a full forensic investigation.

How does this compare to other major crypto exchange hacks?
At $387.5 million, this is the largest confirmed crypto exchange hack of 2026, though it remains smaller than the $1.4 billion Bybit hack in February 2025, which the FBI later formally attributed to North Korea.

This article is for informational purposes only and does not constitute financial or security advice. Always do your own research and review an exchange’s security practices before depositing funds. Data referenced from Decrypt, Yahoo Finance, and Fortune, as of September 26, 2026.

Disclaimer: This content was generated with the assistance of artificial intelligence (AI) and has been reviewed by our editorial team. It is intended for informational purposes only and should not be construed as financial, investment, or legal advice. Cryptocurrency investments involve significant risk.
KCEX BLOGKCEX BLOG
Previous 2026-09-22 23:43
Next 3 days ago

Related Posts

SHARE
TOP

Discover more from KCEX BLOG

Subscribe now to keep reading and get access to the full archive.

Continue reading