North Korea Suspected in $351 Million Bitget Crypto Heist
Bitget, a centralized cryptocurrency exchange, suffered an unauthorized transfer of approximately $351.6 million in digital assets on September 24, 2026. The attack involved the compromise of a critical backend system in the wallet infrastructure, allowing fraudulent transfers without compromising private keys. The stolen funds originated from a small number of hot wallets, while cold wallets remained unaffected. The attack method resembles known North Korean hacker group tactics, though specific attribution details have not been disclosed. Some attacker-linked wallet addresses have been frozen by blockchain foundations. Investigations are ongoing with assistance from Mandiant and SlowMist.
AI Analysis
Technical Summary
On September 24, 2026, Bitget detected unauthorized transfers totaling about $351.6 million across multiple cryptocurrencies including ETH, XRP, BNB, AVAX, USDT, and USDC. The attacker exploited a critical backend system within Bitget's wallet infrastructure to approve fraudulent transfers without accessing private keys. The funds were taken from hot wallets; cold wallets were not compromised. Bitget's CEO indicated that the attack patterns and IP behavior are consistent with North Korean state-sponsored hacker groups, though no specific group was named. Some blockchain foundations have frozen wallet addresses linked to the attacker. The incident has been reported to authorities, and cybersecurity firms Mandiant and SlowMist are assisting with the investigation.
Potential Impact
The attacker successfully transferred approximately $351.6 million in cryptocurrency from Bitget's hot wallets, impacting multiple blockchain assets, with XRP suffering the largest loss on a single chain. The compromise affected Bitget's backend wallet infrastructure but did not involve private key theft or cold wallet compromise. The incident represents a significant financial loss and potential reputational damage to Bitget. Some attacker-linked wallet addresses have been frozen, potentially limiting further fund movement.
Mitigation Recommendations
Bitget's security systems detected and halted unauthorized transfers promptly, and some attacker-linked wallet addresses have been frozen by blockchain foundations. The company is investigating the root cause with external cybersecurity experts. No private keys were compromised, and cold wallets remain secure. Users of Bitget Wallet, which operates on separate infrastructure, were not affected. Stakeholders should monitor official updates from Bitget and relevant authorities. Patch status is not applicable as this is an incident involving operational security compromise rather than a software vulnerability.
North Korea Suspected in $351 Million Bitget Crypto Heist
Description
Bitget, a centralized cryptocurrency exchange, suffered an unauthorized transfer of approximately $351.6 million in digital assets on September 24, 2026. The attack involved the compromise of a critical backend system in the wallet infrastructure, allowing fraudulent transfers without compromising private keys. The stolen funds originated from a small number of hot wallets, while cold wallets remained unaffected. The attack method resembles known North Korean hacker group tactics, though specific attribution details have not been disclosed. Some attacker-linked wallet addresses have been frozen by blockchain foundations. Investigations are ongoing with assistance from Mandiant and SlowMist.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
On September 24, 2026, Bitget detected unauthorized transfers totaling about $351.6 million across multiple cryptocurrencies including ETH, XRP, BNB, AVAX, USDT, and USDC. The attacker exploited a critical backend system within Bitget's wallet infrastructure to approve fraudulent transfers without accessing private keys. The funds were taken from hot wallets; cold wallets were not compromised. Bitget's CEO indicated that the attack patterns and IP behavior are consistent with North Korean state-sponsored hacker groups, though no specific group was named. Some blockchain foundations have frozen wallet addresses linked to the attacker. The incident has been reported to authorities, and cybersecurity firms Mandiant and SlowMist are assisting with the investigation.
Potential Impact
The attacker successfully transferred approximately $351.6 million in cryptocurrency from Bitget's hot wallets, impacting multiple blockchain assets, with XRP suffering the largest loss on a single chain. The compromise affected Bitget's backend wallet infrastructure but did not involve private key theft or cold wallet compromise. The incident represents a significant financial loss and potential reputational damage to Bitget. Some attacker-linked wallet addresses have been frozen, potentially limiting further fund movement.
Defensive Guidance
Bitget's security systems detected and halted unauthorized transfers promptly, and some attacker-linked wallet addresses have been frozen by blockchain foundations. The company is investigating the root cause with external cybersecurity experts. No private keys were compromised, and cold wallets remain secure. Users of Bitget Wallet, which operates on separate infrastructure, were not affected. Stakeholders should monitor official updates from Bitget and relevant authorities. Patch status is not applicable as this is an incident involving operational security compromise rather than a software vulnerability.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/north-korea-suspected-in-351-million-bitget-crypto-heist/","fetched":true,"fetchedAt":"2026-09-25T14:17:50.632Z","wordCount":1026}
Threat ID: 6ab6828ef7a7c54106de63f2
Added to database: 09/25/2026, 14:17:50 UTC
Last enriched: 09/25/2026, 14:17:55 UTC
Last updated: 09/25/2026, 21:51:11 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.