Bitget Breach: $400M Stolen Through Public Discord and Telegram Channels
Nearly $400 million has been stolen from Bitget's hot and warm wallets in one of the largest digital asset thefts of 2026. The breach, which occurred on September 24, saw the attackers use a third-party backend system compromise to spoof transaction data and bypass internal authorization processes.
The attackers have laundered the funds through public Discord servers and Telegram groups, using bridging services and mixers like Wasabi to obscure the transaction trail. Blockchain investigator ZachXBT has identified specific usernames involved in the operation, including cc02006 and jack_34808, which are linked to North Korea-affiliated groups operating under aliases like TraderTraitor and Lazarus.
The investigation is ongoing, with Bitget working alongside Mandiant and SlowMist, two respected names in blockchain forensics and cybersecurity. The exchange has also suspended withdrawals immediately following the breach and resumed them in phases starting September 28. Private keys were never compromised, which meant cold wallets stayed secure.