Bitget Reports $351.6 Million Crypto Theft Linked to Suspected North Korean Hackers
Cryptocurrency exchange Bitget has reported that suspected North Korean threat actors stole approximately $351.6 million from a limited number of its hot and warm wallets.
Bitget said its security systems detected unauthorized transfers at 18:31 UTC on September 24, 2026.
The company said its cold wallets and the majority of platform assets remain secure and unaffected.
Customer Accounts Remain Unaffected
Bitget said customer account balances remain accurate and that deposits and trading services continue to operate normally.
However, the exchange temporarily suspended withdrawals while it conducts a comprehensive security review.
Bitget has also brought in Mandiant and SlowMist to assist with the investigation.
The company said Bitget Wallet, its self-custodial wallet service, operates on separate infrastructure and was not affected by the incident.
Cryptocurrencies and Networks Affected
According to Bitget CEO Gracy Chen, the stolen assets include:
- ETH
- XRP
- BNB
- AVAX
- USDT
- USDC
The affected transactions involved several blockchain networks, including:
- Ethereum
- XRP Ledger
- Arbitrum
- Avalanche
- Optimism
- BNB Smart Chain
- Base
Bitget said it has contacted the foundations and organizations associated with the affected networks. Some have reportedly confirmed that attacker-controlled wallet addresses have been frozen.
Backend System Was Compromised
Bitget said the attacker compromised a critical backend system within its wallet infrastructure.
According to the company's preliminary findings, the attacker used the compromised system to spoof transaction data and trigger the exchange's authorization process, allowing funds to be transferred out.
Bitget said the specific method used to initially compromise the backend system remains under investigation.
The company stated that no further unauthorized transfers are currently possible.
Suspected North Korean Connection
Bitget said its analysis of IP behavior and blockchain activity showed patterns it considers highly consistent with previously observed North Korean hacking operations.
However, the attribution remains part of the ongoing investigation.
The incident follows other major cryptocurrency thefts attributed to North Korea-linked groups, including the reported $1.5 billion Bybit theft and the $292 million KelpDAO LayerZero bridge theft.
Key Takeaway
Bitget has reported approximately $351.6 million in unauthorized cryptocurrency transfers from a limited number of hot and warm wallets.
The exchange says customer balances and most platform assets remain secure, while withdrawals have been temporarily suspended during the investigation. Mandiant and SlowMist are assisting with the forensic analysis, while the exact initial intrusion method and final attribution remain under investigation.