Skip to main content

North Korea Suspected in $351 Million Bitget Crypto Heist

0
Critical
News
Published: 09/25/2026 (09/25/2026, 14:16:18 UTC)
Source: SecurityWeek

Description

Bitget, a centralized cryptocurrency exchange, suffered an unauthorized transfer of approximately $351.6 million in digital assets on September 24, 2026. The attack involved the compromise of a critical backend system in the wallet infrastructure, allowing fraudulent transfers without compromising private keys. The stolen funds originated from a small number of hot wallets, while cold wallets remained unaffected. The attack method resembles known North Korean hacker group tactics, though specific attribution details have not been disclosed. Some attacker-linked wallet addresses have been frozen by blockchain foundations. Investigations are ongoing with assistance from Mandiant and SlowMist.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/25/2026, 14:17:55 UTC

Technical Analysis

On September 24, 2026, Bitget detected unauthorized transfers totaling about $351.6 million across multiple cryptocurrencies including ETH, XRP, BNB, AVAX, USDT, and USDC. The attacker exploited a critical backend system within Bitget's wallet infrastructure to approve fraudulent transfers without accessing private keys. The funds were taken from hot wallets; cold wallets were not compromised. Bitget's CEO indicated that the attack patterns and IP behavior are consistent with North Korean state-sponsored hacker groups, though no specific group was named. Some blockchain foundations have frozen wallet addresses linked to the attacker. The incident has been reported to authorities, and cybersecurity firms Mandiant and SlowMist are assisting with the investigation.

Potential Impact

The attacker successfully transferred approximately $351.6 million in cryptocurrency from Bitget's hot wallets, impacting multiple blockchain assets, with XRP suffering the largest loss on a single chain. The compromise affected Bitget's backend wallet infrastructure but did not involve private key theft or cold wallet compromise. The incident represents a significant financial loss and potential reputational damage to Bitget. Some attacker-linked wallet addresses have been frozen, potentially limiting further fund movement.

Defensive Guidance

Bitget's security systems detected and halted unauthorized transfers promptly, and some attacker-linked wallet addresses have been frozen by blockchain foundations. The company is investigating the root cause with external cybersecurity experts. No private keys were compromised, and cold wallets remain secure. Users of Bitget Wallet, which operates on separate infrastructure, were not affected. Stakeholders should monitor official updates from Bitget and relevant authorities. Patch status is not applicable as this is an incident involving operational security compromise rather than a software vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/north-korea-suspected-in-351-million-bitget-crypto-heist/","fetched":true,"fetchedAt":"2026-09-25T14:17:50.632Z","wordCount":1026}

Threat ID: 6ab6828ef7a7c54106de63f2

Added to database: 09/25/2026, 14:17:50 UTC

Last enriched: 09/25/2026, 14:17:55 UTC

Last updated: 09/25/2026, 21:51:11 UTC

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses