Bitget, the Seychelles-headquartered cryptocurrency exchange, lost $387.5 million on September 24, 2026, when attackers exploited a zero-day vulnerability in a third-party security product to spoof withdrawal requests through the exchange's own authorization system. The breach ranks as the larges...
"We are not expecting to recover a lot of funds." — Gracy Chen, CEO, Bitget (CNBC, October 2, 2026)
Bitget, the Seychelles-headquartered cryptocurrency exchange, lost $387.5 million on September 24, 2026, when attackers exploited a zero-day vulnerability in a third-party security product to spoof withdrawal requests through the exchange's own authorization system. The breach ranks as the largest single crypto exchange theft of 2026 and the second-largest in industry history, behind only the $1.4 billion Bybit exploit of February 2025.
On October 1, blockchain analytics firm Chainalysis published attribution findings linking the attack to threat actors associated with the Democratic People's Republic of Korea (DPRK). The firm traced 23 outbound transfers across four blockchains — Ethereum (49.7% of stolen funds), XRP Ledger (40.8%), Zcash (7.6%), and Tron (1.8%) — completed within approximately three hours of the initial breach. With the Bitget loss included, DPRK-linked actors have now stolen more than $1 billion in cryptocurrency during 2026 alone, according to both Chainalysis and Elliptic. TRM Labs data shows North Korean groups accounted for 76% of all crypto hack losses in 2026 through April.
As of October 2, Bitget has frozen $1.1 million of the stolen $387.5 million. CEO Gracy Chen told CNBC she does not expect significant recovery. The exchange absorbed the loss using its Protection Fund and corporate reserves, maintaining a reported 131% reserve ratio across 19 covered assets.
The breach began at 18:31 UTC on September 24, 2026, with two small test transfers designed to stay below Bitget's automated risk-control thresholds. These transactions raised no alerts. Approximately 30 minutes later, larger transfers commenced and continued until Bitget's reconciliation system flagged balance discrepancies at 19:05 UTC, at which point the exchange halted withdrawals.
The attack vector was not a private key compromise. According to Bitget and third-party investigators Mandiant (Google-owned) and SlowMist, the attacker exploited a zero-day vulnerability in an unnamed third-party security product deployed within Bitget's infrastructure. The vulnerability allowed the attacker to gain elevated credentials for Bitget's internal network.
SlowMist's forensic analysis recovered a deleted tool purpose-built to manipulate Bitget's withdrawal process. The tool forged risk-control parameters, constructed withdrawal requests, and triggered the wallet system to process them as legitimate transactions. In effect, the exchange's own signing infrastructure authorized the theft — a technique classified as data spoofing, distinct from the interface spoofing used in the February 2025 Bybit attack.
The breach was confined to hot and warm wallets. Cold wallets remained uncompromised, according to Bitget's incident report.
Bitget has not publicly named the compromised security product. The company described the vulnerability as a zero-day, meaning no patch was available at the time of exploitation.
Chainalysis published its forensic findings on October 1, documenting the movement of $387.5 million across four blockchain networks within the first three hours of the attack:
| Blockchain | Share of Stolen Funds | Approximate Value | |---|---|---| | Ethereum | 49.7% | ~$192.6M | | XRP Ledger | 40.8% | ~$158.1M | | Zcash | 7.6% | ~$29.5M | | Tron | 1.8% | ~$7.0M |
The attackers converted approximately $100 million in stablecoins (USDT, USDC) to ETH shortly after exfiltration — a standard countermeasure against centralized freezing by stablecoin issuers. An additional $85 million was already denominated in ETH at the time of theft. Approximately $157.5 million in XRP and $7 million in TRX remained unconverted in the initial post-breach window.
Much of the stolen XRP was subsequently routed through cross-chain liquidity protocols, including THORChain, and converted to Bitcoin — a laundering pattern consistent with prior DPRK-attributed operations. The use of Zcash, a privacy-focused cryptocurrency, for 7.6% of the stolen funds adds an obfuscation layer that complicates chain-based tracing.
Chainalysis reported that its AI-assisted tracing tools compressed what would normally require more than 20 hours of manual cross-chain bridge reconciliation into under 10 minutes. The firm said its custom automations matched deposits and payouts across protocols using more than a decade of cross-chain attribution data, though human investigators defined the tracing logic, reviewed automated results, and directed the investigation.
Chainalysis attributed the Bitget attack to DPRK-linked threat actors based on several factors. The firm traced 23 transfers completed within three hours across four chains, identifying on-chain behavioral patterns consistent with prior attributed DPRK operations.
Bitget CEO Gracy Chen cited IP behavior and blockchain activity consistent with North Korean groups in her initial public statements. Chen stated: "The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out."
The laundering methodology observed post-breach follows a documented DPRK playbook, according to multiple forensics firms:
This pattern closely mirrors the Bybit breach of February 2025 ($1.4 billion), which the FBI formally attributed to North Korea's Lazarus Group. In that case, Lazarus laundered approximately $900 million through THORChain, according to DL News reporting.
The Bitget breach pushes cumulative DPRK-attributed crypto theft in 2026 past $1 billion, according to Chainalysis and Elliptic. TRM Labs data provides further context on the scale of North Korean cyber-theft operations:
| Metric | Value | |---|---| | DPRK-attributed crypto theft in 2026 (through Oct.) | >$1 billion | | DPRK share of 2026 crypto hack losses (through Apr.) | 76% | | Total DPRK-attributed theft since 2017 | >$6 billion | | Total DPRK-attributed theft since 2016 (Skynet report) | $6.75 billion across 263 incidents |
The DPRK share of global crypto hack losses has escalated consistently: below 10% in 2020–2021, 22% in 2022, 37% in 2023, 39% in 2024, 64% in 2025, and 76% in 2026 through April, according to TRM Labs.
Major 2026 incidents attributed to North Korean actors include:
According to The Block, citing TRM Labs, DPRK actors accounted for just 3% of total hack incidents in 2026 through April but captured 76% of total dollar losses — indicating a concentration on high-value targets with large hot wallet balances.
Bitget suspended withdrawals immediately after detecting the breach. Bitcoin withdrawals resumed September 28, Ethereum on September 29, and USDT on September 30. Other token withdrawals returned October 2.
The exchange stated that no customer balances were written down. Bitget cited its User Protection Fund — which held over $464 million pre-breach — as the backstop. Chen said the fund, combined with more than $1 billion in Bitget's own assets, covers user funds on a 1:1 basis. The Protection Fund has since been replenished to more than $300 million, according to the company.
Bitget's latest Proof of Reserves disclosure reported an overall reserve ratio of 131% across 19 covered assets.
Recovery efforts remain minimal. As of October 2, $1.1 million of the $387.5 million has been frozen across cooperating platforms. Bitget launched a recovery bounty program offering 5% of successfully frozen or recovered funds to platforms that voluntarily freeze attacker-controlled wallets, with an additional 5% if the funds are ultimately recovered.
Chen's assessment on CNBC on October 2 was blunt: "We are not expecting to recover a lot of funds," citing the historically low recovery rates from prior exchange hacks. For reference, the $1.4 billion Bybit hack of 2025 saw limited recovery, with the majority of funds laundered within weeks through THORChain and other cross-chain venues.
The Bitget breach exposes a structural vulnerability in centralized exchange security: third-party supply chain risk. Unlike the Bybit hack, which targeted the human-machine interface (a spoofed signing screen), the Bitget attack targeted the machine-to-machine layer — backend infrastructure that processes withdrawal requests. This distinction is significant.
The attack succeeded without compromising private keys, bypassing multisignature protections, or breaching cold storage. The exchange's signing infrastructure was co-opted through legitimate internal credentials obtained via a zero-day in a security vendor's product. The implication: an exchange's security posture is bounded by the weakest link in its vendor stack.
Three structural questions emerge:
Vendor disclosure: Bitget has not named the compromised security product. Other exchanges may use the same product. Without disclosure, the zero-day may remain unpatched across the industry.
Hot wallet exposure: Both the Bybit and Bitget hacks targeted hot and warm wallet systems. Cold wallets remained intact in both cases. The recurring pattern suggests that exchanges with large hot wallet balances face outsized risk from operational-layer attacks.
Cross-chain laundering infrastructure: THORChain and similar no-KYC cross-chain swap protocols continue to function as primary laundering rails for DPRK-linked actors. The same infrastructure featured in the Bybit laundering operation reappeared in the Bitget case. This creates a policy question about whether decentralized protocols can — or should — implement screening mechanisms for stolen assets.
The Bitget hack represents the continuation of an accelerating trend: state-sponsored actors systematically targeting centralized exchange infrastructure for nine-figure payouts. The economic value at stake is not in protocol-level vulnerabilities but in the operational layer — the vendor software, internal APIs, and authorization workflows that connect cold storage to the public internet.
Bitget's ability to absorb a $387.5 million loss without writing down customer balances demonstrates the financial resilience of larger exchanges. But the $1.1 million frozen out of $387.5 million stolen illustrates the asymmetry between attack velocity and recovery capacity. Once assets cross into no-KYC cross-chain protocols, recovery rates approach zero.
The undisclosed identity of the compromised security vendor remains the most immediate systemic concern. Until the product is named and patched, the same zero-day may be exploitable across other exchanges. The industry's security architecture is only as strong as its least-audited vendor dependency.