Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

MediumThe Hacker News · info@thehackernews.com (The Hacker News)·

At a glance

Severity
Medium
Used in attacks
No flaws named
Vendors and products
Exchange
Industries
Finance
Reported by
1 outlet

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.

"At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," BitGet said in a post shared on X. "Bitget's cold wallets and the overwhelming majority of platform assets remain secure and unaffected."

The company emphasized that customer account balances remain accurate, and deposits and trading continue to operate normally. However, withdrawals have been temporarily suspended out of an abundance of caution while a "comprehensive security review" is underway.

Bitget did not disclose any details on how the attack took place, but said it has enlisted the help of Google-owned Mandiant and SlowMist for a third-party investigation.

"Bitget Wallet operates as a self-custodial wallet on a completely separate and independent infrastructure from Bitget Exchange and was not affected by this incident," it noted.

According to Bitget CEO Gracy Chen, assets impacted by the hack include ETH, XRP, BNB, AVAX, USDT, and USDC, with the chains involving Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base.

"We have contacted the foundations of all affected chains, and some foundations have confirmed the freezing of hacker wallet addresses," Chen said. "Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations."

"The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation."

The development comes about a week after SentinelOne attributed the North Korea-linked TraderTraitor group to an attack targeting an India-based information technology (IT) services company. TraderTraitor is best known for the theft of $1.5 billion from Bybit and $292 million from KelpDAO's LayerZero bridge.

Originally published by The Hacker News. © The Hacker News. Written by info@thehackernews.com (The Hacker News).

Fastnexa security experts

Dealing with this in your own company?

If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.

Book a 30-min callWhatsApp us

Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →

Coverage

One outlet has carried this so far.

  1. The Hacker News ↗Established SourceFirst reported

    2026-09-25 10:35 UTC

Related stories

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise | CyberBrief