Skip to content
Back to Guavy Wire
Crypto

Bitget Breach: $400M Stolen Through Public Discord and Telegram Channels

Share

Nearly $400 million has been stolen from Bitget's hot and warm wallets in one of the largest digital asset thefts of 2026. The breach, which occurred on September 24, saw the attackers use a third-party backend system compromise to spoof transaction data and bypass internal authorization processes.

The attackers have laundered the funds through public Discord servers and Telegram groups, using bridging services and mixers like Wasabi to obscure the transaction trail. Blockchain investigator ZachXBT has identified specific usernames involved in the operation, including cc02006 and jack_34808, which are linked to North Korea-affiliated groups operating under aliases like TraderTraitor and Lazarus.

The investigation is ongoing, with Bitget working alongside Mandiant and SlowMist, two respected names in blockchain forensics and cybersecurity. The exchange has also suspended withdrawals immediately following the breach and resumed them in phases starting September 28. Private keys were never compromised, which meant cold wallets stayed secure.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc