Editor's Pick

Bitget Says $350 Million Hack Is Likely Linked to North…

Bitget says North Korean hackers are “very likely” to have been behind the approximately $351.6 million theft from the cryptocurrency exchange, citing preliminary technical evidence discovered during its investigation into one of the largest crypto security incidents of 2026.

CEO Gracy Chen said investigators identified IP addresses associated with the attack that matched VPN services previously used by a hacking group linked to the Democratic People’s Republic of Korea.

“We’ve identified some IP addresses that match the VPN choices by a certain DPRK group,” Chen said during a live discussion following the breach. She added that the attack pattern resembled techniques previously associated with North Korean hackers.

The attribution remains preliminary. Bitget has not published a completed forensic report establishing that a particular North Korean group carried out the attack, and no government agency has publicly attributed the breach to Pyongyang.

Attackers Breached Backend Systems, Bitget Says

Bitget first detected unauthorized transfers at 18:31 UTC on September 24, estimating that approximately $351.6 million in assets were affected.

The exchange said its cold wallets remained secure and that the breach was contained to portions of its hot and warm wallet infrastructure. Withdrawals were temporarily suspended while deposits and trading continued operating.

Bitget’s preliminary investigation also points away from a conventional private-key theft.

Chen said the attackers did not obtain private keys controlling the exchange’s cold, hot or warm wallets. Instead, investigators believe they compromised a critical backend system and were able to generate fraudulent transfer instructions that passed through Bitget’s authorization infrastructure.

The company is also investigating whether a third-party software component could have provided an initial entry point, although the precise attack vector has not been conclusively established.

Onchain investigators initially identified roughly $180 million to $190 million moving from Bitget-linked addresses. Subsequent tracking uncovered additional assets, including approximately 102.9 million XRP, helping reconcile early blockchain estimates with Bitget’s substantially higher $351.6 million figure. SlowMist’s MistTrack identified 11 EVM addresses, seven XRP Ledger addresses and one Tron address associated with the incident.

North Korea Attribution Remains Preliminary

The suspected North Korean connection is significant because state-linked hacking groups have repeatedly targeted cryptocurrency infrastructure.

North Korea was formally blamed by the FBI for the $1.5 billion Bybit theft in February 2025, which U.S. authorities attributed to DPRK-linked TraderTraitor actors. The attack became the largest publicly disclosed cryptocurrency theft and demonstrated the ability of North Korean operators to compromise infrastructure surrounding institutional wallet systems.

Bitget has not yet established an equivalent attribution for its own breach.

Chen said the exchange currently considers insider involvement unlikely and pointed instead to the VPN evidence and similarities with previous DPRK-associated operations. Independent researchers have also noted similarities in the attackers’ rapid conversion of stablecoins into ETH, but transaction behavior alone cannot conclusively identify an attacker.

Bitget says customer balances remain intact despite the theft. Its User Protection Fund currently contains more than $464 million, exceeding the exchange’s estimated $351.6 million loss. The company says the fund is sufficient to cover the incident in full.

Law-enforcement agencies and blockchain-security companies have been notified, while addresses associated with the attackers have been flagged.

The exchange has also said some stolen assets could potentially be recovered or frozen as investigators work with blockchain networks and other industry participants.

For now, the strongest conclusion is narrower than a confirmed North Korean attribution: Bitget itself believes a DPRK-linked hacking group is a highly likely suspect based on preliminary technical evidence.

A definitive finding will depend on the exchange’s completed forensic investigation and any subsequent attribution by independent security researchers or law-enforcement authorities.