Bitget, the Seychelles-based cryptocurrency exchange, confirmed on September 24 that attackers drained $387.5 million from its hot and warm wallets in what is now the largest single exchange breach of 2026. The initial damage estimate of $351.6 million was revised upward after investigators trace...
"North Korea was very likely behind this attack. The IP addresses match the VPN choices by a certain DPRK group." — Gracy Chen, CEO, Bitget
Bitget, the Seychelles-based cryptocurrency exchange, confirmed on September 24 that attackers drained $387.5 million from its hot and warm wallets in what is now the largest single exchange breach of 2026. The initial damage estimate of $351.6 million was revised upward after investigators traced additional stolen assets on the Zcash and Tron networks. Bitget CEO Gracy Chen attributed the attack to North Korean state-linked hackers, citing IP address evidence and transaction pattern analysis consistent with prior DPRK operations.
The breach pushes September 2026 crypto losses past $684 million, making it the costliest month of the year. North Korean-linked actors have now stolen more than $1 billion in crypto assets in 2026 alone, according to analytics firm Elliptic, and more than $6.75 billion cumulatively since 2017, according to TRM Labs. The Bitget incident underscores a structural problem in centralized exchange security: backend system compromises that bypass private key protections entirely.
Bitget's $464 million User Protection Fund covers the loss with approximately $76 million to spare. The exchange has paused withdrawals but kept deposits and trading operational, and CEO Chen confirmed IPO plans remain on track within a three-year window.
Bitget's security systems flagged unauthorized transfers at 18:31 UTC on September 24. The exchange activated emergency response protocols within minutes, according to CEO Chen's public statements.
The attack vector was not a private key compromise. According to CoinDesk's reporting, the attacker breached a critical backend system within Bitget's wallet infrastructure and used it to spoof transaction data — effectively fabricating transfer requests that tricked the exchange's authorization-signing process into approving withdrawals. Chen described it as the digital equivalent of a forged deposit slip: the system believed it was processing legitimate internal transfers.
This method is notable because it circumvents the security model that most exchanges rely on. Cold wallets, held offline with air-gapped key storage, remained untouched. The vulnerability existed in the software layer between the exchange's operational systems and its hot wallet signing infrastructure.
The affected wallets held Ether (ETH), XRP, BNB, Avalanche (AVAX), Tether (USDT), USD Coin (USDC), and other altcoins. Chen confirmed that cold storage was not compromised.
The largest component of the theft was approximately 103 million XRP, worth roughly $157 million at the time of the breach. The remaining balance consisted of ETH, stablecoins, and smaller altcoin positions across multiple blockchain networks.
On-chain analysis, tracked in real time by Bubblemaps and Arkham Intelligence, revealed a methodical laundering sequence:
Stablecoin conversion (first 6 minutes): The attacker prioritized converting $19.7 million in USDT to ETH within six minutes, paying up to 5% above market price for speed. This urgency reflected awareness that Tether and Circle can freeze stablecoin addresses — though in this case, the two issuers managed to freeze only $318,000 combined, approximately 0.1% of the stablecoin total.
XRP movement: On September 26, the hacker moved approximately $83 million in stolen XRP out of three holding wallets. An additional $75 million in XRP remained in accounts that cannot be frozen under the XRP Ledger's existing protocol rules. Unlike USDT or USDC, XRP has no centralized freeze mechanism — Ripple cannot unilaterally lock tokens on the network.
Conversion to Bitcoin: According to Bitquery's investigation, the attacker moved nearly all stolen TRX and BNB, and every exit traced to its endpoint so far terminates in Bitcoin, consistent with North Korean laundering patterns observed in prior incidents.
Chen stated publicly that North Korea was "very likely" behind the breach, citing IP addresses linked to VPN services previously used by DPRK cyber units. She did not name a specific group.
Blockchain investigator Specter Analyst went further, claiming the Lazarus Group specifically was responsible. Specter linked the Bitget hack to the $24 million AFX exchange hack in July 2026, which was attributed to TraderTraitor (a North Korean hacking unit), noting that stolen XRP from Bitget was bridged and can be directly connected to funds from the AFX incident.
The attribution is not unanimous. Some security researchers noted that "Lazarus Group" functions as a collective label for various North Korean cyber operations rather than a single cohesive unit. The laundering patterns are consistent with DPRK methodology, but definitive attribution to a specific sub-group remains contested.
Bloomberg reported on September 25 that the Bitget hack pushed North Korea's 2026 crypto theft total past $1 billion. TRM Labs data shows North Korean-linked hackers stole approximately $643 million in the first half of 2026 alone, accounting for roughly two-thirds of all crypto funds stolen worldwide in that period. Approximately 90% of North Korea's H1 proceeds — about $577 million — came from just two attacks on DeFi platforms in April: a $285 million drain of Drift (Solana-based futures exchange) and a $292 million exploit of KelpDAO.
Cumulatively since 2017, North Korea has stolen approximately $6.75 billion in cryptocurrency, according to TRM Labs, making it the most prolific state-sponsored crypto theft operation documented.
Bitget's response followed a now-familiar playbook for exchange breaches:
The existence and adequacy of the User Protection Fund distinguishes this breach from historical catastrophes like the Mt. Gox collapse. Whether the fund's structure — self-reported, exchange-managed, without independent audit verification publicly available — provides sufficient assurance is a separate question.
The market response to the breach was muted:
The contained reaction suggests traders priced the breach as a Bitget-specific event rather than a systemic risk to centralized exchanges. The rapid disclosure and the existence of the protection fund likely constrained panic selling. This represents a material shift from earlier years, when exchange hacks routinely triggered market-wide drawdowns.
Multiple exchange executives publicly offered assistance within hours of the disclosure:
The coordinated response from rival exchanges is notable. It reflects both industry maturation and a shared interest in preventing a single breach from becoming a sector-wide crisis of confidence — a pattern that has recurred with increasing frequency since the Bybit hack in 2025.
The Bitget breach fits into a broader 2026 security environment:
| Metric | Value | |--------|-------| | Total 2026 incidents (through September) | 288 | | Total 2026 losses | ~$2.21 billion | | September 2026 losses | ~$684 million (highest month) | | Previous worst month (April 2026) | ~$646.9 million | | North Korea's share of 2026 theft | ~76% of total value | | North Korea 2026 total | >$1 billion |
According to CoinReporter and CoinPedia, the 288 reported incidents span publicly reported exploits, protocol-level failures, and intermediary compromises. The concentration of value in a small number of large incidents — particularly those attributed to North Korea — indicates that state-sponsored actors, rather than opportunistic hackers, drive the majority of dollar-value losses.
The DeFi Education Fund noted in its September 21 debrief that human-layer attacks (social engineering, backend compromise, insider access) have eclipsed smart contract exploits as the primary attack vector in 2026, a trend the Bitget hack exemplifies.
The Bitget hack exposes a specific failure mode: backend system compromise that bypasses cryptographic key protections. This is not a novel vector — the $234 million WazirX hack in 2024 used a similar approach — but its recurrence at scale raises questions about the industry's middleware security standards.
Three structural observations:
Cold storage is necessary but insufficient. Exchanges routinely cite cold wallet security as evidence of robustness. The Bitget hack confirms that the vulnerability surface extends to the software layer managing hot wallet operations, not just key storage.
Stablecoin freeze mechanisms are too slow. Circle and Tether froze $318,000 of approximately $75 million in stablecoins — a 0.4% interception rate. The attacker converted most stablecoins to ETH within minutes, outpacing the issuers' response capabilities.
XRP's design creates an asymmetry. The XRP Ledger's lack of a centralized freeze mechanism meant $157 million in stolen XRP was effectively unrecoverable through issuer intervention, unlike USDT or USDC. This design trade-off — decentralization versus recoverability — has direct economic consequences in breach scenarios.
The Bitget breach is the third nine-figure exchange hack attributed to North Korean actors in 2026. The attack pattern — backend compromise, not key theft — has been documented in multiple prior incidents and continues to succeed at scale. The exchange's protection fund appears adequate for this specific loss, but the incident raises a broader question about the industry's middleware security posture that protection funds alone cannot answer.
The muted market response and coordinated industry support suggest the crypto exchange sector has developed a higher tolerance for breach events, supported by reserve funds, rapid disclosure, and inter-exchange cooperation. Whether that tolerance reflects genuine resilience or complacency will be tested by the next incident.
North Korea's $1 billion-plus haul in 2026 — on pace to exceed 2025's $2.02 billion — represents a national security dimension that operates independently of market sentiment. The economic value extracted by state-sponsored actors from the crypto ecosystem is now a line item in geopolitical risk models, not merely a cybersecurity footnote.