Bitget Hack Attributed to North Korea, $387M Stolen, and More
The Bitget hack, which occurred on September 24, 2026, has been attributed to actors with ties to North Korea by the analytics firm Chainalysis. The breach resulted in the theft of around $387 million, spread across 23 individual transfers within three hours. The funds were distributed across four chains: 49.7% on Ethereum, 40.8% on XRP, 7.6% on Zcash, and 1.8% on Tron. Chainalysis notes that the split is not a coincidence, but rather a division of labor between liquidity, speed, and shielding.
The analysts' attribution is based on patterns, including recurring addresses, known exchange services, and typical sequences used in obfuscation. However, they caution that the statement about who sat at the keyboard is not definitive and that the attribution is a statement of probability. The firm's statement notes that the attribution to DPRK-linked actors changes the probability that the same method resurfaces in three months.
The report also highlights the use of cross-chain bridges and mixers to obfuscate the trail of the stolen funds. Chainalysis notes that these tools are not forbidden in themselves and have legitimate uses, but they can produce a sequence that costs investigators time. The firm has deployed an in-house AI automation to match transfers across bridges, cutting the time for manual work to under ten minutes.