Data Breaches Strongly negative 8

North Korean Suspects in Bitget's $351.6M Multi-Chain Crypto Heist

Bitget's hot and warm wallet compromise shows attackers moved beyond credential theft into backend transaction-signing infrastructure. Multi-chain impact across Ethereum, XRP Ledger, Arbitrum, and others totals $351.6M, with North Korean groups suspected. The $464M User Protection Fund covers losses, but withdrawal suspension signals ongoing containment.

· 4 min read · Verified by 2 sources ·

Beat this week

Last 7 days · Data Breaches

9 stories
7.2 avg impact
0% positive
89% negative
vs prior 7 days +3 +3 stories vs prior 7 days

Impact 7.2/10 (-0.8 vs prior). Counts are stories in our record, not a market forecast.

Open the change report

Coverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 89 percentage points.

  • 11% neutral
  • 89% negative

This story sits in Data Breaches — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.

Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.

Cybersecurity briefing

Key takeaways

8 impact
Strongly negativesentiment
2sources
4min read
  1. Bitget's hot and warm wallet compromise shows attackers moved beyond credential theft into backend transaction-signing infrastructure.
  2. Multi-chain impact across Ethereum, XRP Ledger, Arbitrum, and others totals $351.6M, with North Korean groups suspected.
  3. The $464M User Protection Fund covers losses, but withdrawal suspension signals ongoing containment.
Drawn from
  • BleepingComputer
  • TechCrunch

In this briefing

Mentioned

Key Intelligence

Key Facts

  1. 1Suspected North Korean hackers stole $351.6 million from Bitget hot and warm wallets, the largest crypto heist of 2026.
  2. 2Affected chains included Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base; XRP was the largest single-chain loss.
  3. 3Bitget User Protection Fund holds 5,500 BTC worth about $464 million, exceeding the loss and covering affected customers.
  4. 4Withdrawals suspended while law enforcement, Mandiant, and SlowMist investigate; deposits and trading continue and Bitget Wallet was unaffected.
  5. 5TRM Labs attributes about 75% of 2026 crypto thefts to North Korea.
  6. 6The heist exceeded a $340 million September 2026 hack where the hacker returned all but $47 million.

Who's Affected

Bitget
companyNegative
Bitget Users
groupNeutral
North Korean hacking groups
organizationPositive
Other crypto exchanges
companyNegative

Analysis

For security teams, the Bitget breach is not a routine wallet key theft: attackers bypassed the exchange's key backend wallet-service system to forge transfer information and trigger authorization signing across seven chains. The $351.6M exfiltration—largest crypto heist of 2026—underscores how centralized exchanges' warm transaction signing remains a high-value target. Understanding what the intrusion reveals about threat actor tradecraft is critical for defenders.

On September 25, 2026, cryptocurrency exchange Bitget disclosed that suspected North Korean hackers stole approximately $351.6 million from a limited number of its hot and warm wallets, making it the largest known digital-currency heist of the year. The breach was discovered Thursday evening, September 24, when internal security systems flagged multiple unauthorized transfers. Bitget has suspended all withdrawals while it investigates with law enforcement, on-chain security firms SlowMist and Mandiant. The company says its cold wallets and the overwhelming majority of platform assets remain secure, and that its $464 million User Protection Fund will cover the loss.

Bitget CEO Gracy Chen said the attack touched the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base chains, affecting ETH, XRP, BNB, AVAX, USDT, USDC, and other tokens; XRP represented the largest single-chain loss.

The scope and mechanics set this incident apart. Bitget CEO Gracy Chen said the attack touched the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base chains, affecting ETH, XRP, BNB, AVAX, USDT, USDC, and other tokens; XRP represented the largest single-chain loss. The company has not yet explained how attackers accessed its key backend wallet-service system, but it confirmed the intruders were able to forge transfer information and trigger the authorization-signing process. That detail implies compromise of internal transaction-approval workflows rather than a simple theft of user credentials or a single private key. It also explains why all withdrawals are paused: if the signing path is suspect, any further withdrawal could expose additional funds.

North Korean attribution remains based on IP behavior patterns and on-chain analysis, not a formal government determination. Yet blockchain intelligence firm TRM Labs notes North Korea is behind roughly three-quarters of all crypto thefts during 2026 to date. These operations are widely understood to fund the country's nuclear weapons program, and they frequently combine social engineering of developers, supply-chain attacks, and custom tooling to bypass exchange controls. Bitget's disclosure fits that profile, though Mandiant and SlowMist are still investigating.

Market and operational impact is substantial but contained by design. Bitget's User Protection Fund holds 5,500 bitcoin, worth about $464 million at the time of disclosure, exceeding the $351.6 million loss. Customer account balances remain accurate, deposits and trading continue, and the self-custodial Bitget Wallet was not affected because it operates on infrastructure independent of Bitget Exchange. Still, several chains have confirmed freezing hacker wallet addresses, which may limit laundering. The exchange has not said when withdrawals will reopen.

The heist eclipses a $340 million September 2026 hack in which the attacker returned all but $47 million. That earlier incident demonstrated a partial recovery; Bitget's outcome will depend on chain-level freezes, law enforcement coordination, and whether any portion can be clawed back. In contrast, this attack involved a broader set of chains and assets, complicating recovery.

What to Watch

For the crypto industry, the Bitget incident is another warning that centralized exchanges must treat their transaction-signing infrastructure as a critical security boundary. Multi-party computation, policy-based approval, hardware security modules, and real-time anomaly detection are increasingly necessary, but this breach suggests even mature operators can be defeated if an attacker reaches the internal wallet-service layer. Regulators are likely to press for more detailed disclosures and proof of reserve, not just proof of solvency. Bitget will need to explain precisely how the authorization-signing process was triggered without authorization and what changes it is making to prevent recurrence.

North Korean groups will likely adapt and continue targeting exchanges, bridges, and custodians. Defenders should expect increased phishing and insider-risk operations against staff with access to signing workflows. The $351.6 million loss, while covered, may still affect user confidence and liquidity if withdrawals remain paused for an extended period. Ultimately, the speed of Bitget's disclosure, the clarity of the fund coverage, and the degree of on-chain forensics shared with the community will determine whether this becomes an operational footnote or a forced industry-wide upgrade to wallet security.

Timeline

Timeline

  1. Unauthorized transfers detected

  2. Bitget discloses $351.6M theft

Source cluster

Primary reporting

2articles

Cite This Page

"North Korean Suspects in Bitget's $351.6M Multi-Chain Crypto Heist." Cyber Intelligence Brief, September 25, 2026. https://getcyberbrief.com/story/bitget-351m-north-korean-crypto-heist-cyber

How we covered this story

Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.