Chainalysis Links $387 Million Bitget Hack to North Korea-Tied Actors
Chainalysis, a blockchain analytics firm, has traced approximately $387 million stolen from the cryptocurrency exchange Bitget to actors linked with the Democratic People's Republic of Korea (DPRK). The breach, which occurred on September 24, 2026, targeted a hot wallet, a wallet connected to the internet, allowing the thieves to transfer funds across 23 transactions within just three hours.
The stolen funds were distributed across four blockchain networks: 49.7% moved through Ethereum, 40.8% through XRP, 7.6% through Zcash, and 1.8% through Tron. This distribution was strategic, leveraging each network's strengths: Ethereum for liquidity, XRP for speed, Zcash for anonymity, and Tron for low-cost stablecoin transfers. The use of Zcash is particularly noteworthy due to its ability to shield transaction details, making it difficult to trace the funds.
Chainalysis's attribution to DPRK-linked actors is based on patterns observed over years, including recurring addresses and typical obfuscation techniques. However, the firm cautions that such attributions are not definitive court rulings but rather statements of probability. The attribution suggests a higher likelihood of repeated attacks, as state-backed teams often operate with long-term strategies.
The incident pushes the total amount of cryptocurrency thefts attributed to DPRK-linked actors in 2026 to over $1 billion. This figure underscores the ongoing risk for investors, particularly those using large, centrally managed exchanges. The Bitget hack alone accounted for nearly a third of the $1.26 billion lost to crypto hacks in the third quarter of 2026.