Bitget Hacked: North Korea-Linked Threat Actors Steal $387M
Bitget, a cryptocurrency exchange, reported a massive hack on September 24, 2026, with estimated losses of $387 million. Chainalysis attributed the theft to North Korea-linked threat actors. The exchange's CEO, Gracy Chen, stated that the involvement of North Korean hackers is 'very likely' based on IP addresses linked to VPN services associated with a North Korean hacking group.
TRM Labs estimated the loss at $351.6 million, based on funds moved from Bitget's hot and warm wallets across seven blockchains. The exchange said its User Protection Fund, worth $464 million, would cover the loss. However, no recovered funds have been confirmed.
The attackers used a cross-chain liquidity protocol to obtain Bitcoin, which then reached attacker-controlled addresses. Chainalysis used its in-house AI tools to reduce the time required to reconcile bridge transactions from 20 hours to under 10 minutes.
Bitget did not report a private-key theft, stating that the attackers compromised a backend system, manipulated transaction data, and caused the exchange to approve unauthorized transfers.