Bitget Reports $351.6 Million Crypto Theft Linked to Suspected North Korean Hackers

Cryptocurrency exchange Bitget has reported that suspected North Korean threat actors stole approximately $351.6 million from a limited number of its hot and warm wallets.

Bitget said its security systems detected unauthorized transfers at 18:31 UTC on September 24, 2026.

The company said its cold wallets and the majority of platform assets remain secure and unaffected.

Customer Accounts Remain Unaffected

Bitget said customer account balances remain accurate and that deposits and trading services continue to operate normally.

However, the exchange temporarily suspended withdrawals while it conducts a comprehensive security review.

Bitget has also brought in Mandiant and SlowMist to assist with the investigation.

The company said Bitget Wallet, its self-custodial wallet service, operates on separate infrastructure and was not affected by the incident.

Cryptocurrencies and Networks Affected

According to Bitget CEO Gracy Chen, the stolen assets include:

  • ETH
  • XRP
  • BNB
  • AVAX
  • USDT
  • USDC

The affected transactions involved several blockchain networks, including:

  • Ethereum
  • XRP Ledger
  • Arbitrum
  • Avalanche
  • Optimism
  • BNB Smart Chain
  • Base

Bitget said it has contacted the foundations and organizations associated with the affected networks. Some have reportedly confirmed that attacker-controlled wallet addresses have been frozen.

Backend System Was Compromised

Bitget said the attacker compromised a critical backend system within its wallet infrastructure.

According to the company's preliminary findings, the attacker used the compromised system to spoof transaction data and trigger the exchange's authorization process, allowing funds to be transferred out.

Bitget said the specific method used to initially compromise the backend system remains under investigation.

The company stated that no further unauthorized transfers are currently possible.

Suspected North Korean Connection

Bitget said its analysis of IP behavior and blockchain activity showed patterns it considers highly consistent with previously observed North Korean hacking operations.

However, the attribution remains part of the ongoing investigation.

The incident follows other major cryptocurrency thefts attributed to North Korea-linked groups, including the reported $1.5 billion Bybit theft and the $292 million KelpDAO LayerZero bridge theft.

Key Takeaway

Bitget has reported approximately $351.6 million in unauthorized cryptocurrency transfers from a limited number of hot and warm wallets.

The exchange says customer balances and most platform assets remain secure, while withdrawals have been temporarily suspended during the investigation. Mandiant and SlowMist are assisting with the forensic analysis, while the exact initial intrusion method and final attribution remain under investigation.