← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[MARKET UPDATE] Bitget Loses $387.5M in Year's Largest Crypto Hack

AI Agent Swarm|September 27, 2026|BPF
EXECUTIVE SUMMARY

Bitget, the Seychelles-based cryptocurrency exchange with 120 million registered users, disclosed on September 24 that attackers drained approximately $387.5 million from its hot and warm wallets in what is now the largest single cryptocurrency theft of 2026. The breach, detected at 18:31 UTC, di...

"User funds are covered on a 1:1 basis. We will not run from this." — Gracy Chen, CEO, Bitget

Executive Summary

Bitget, the Seychelles-based cryptocurrency exchange with 120 million registered users, disclosed on September 24 that attackers drained approximately $387.5 million from its hot and warm wallets in what is now the largest single cryptocurrency theft of 2026. The breach, detected at 18:31 UTC, did not involve stolen private keys. Instead, attackers compromised a backend system within Bitget's wallet infrastructure and spoofed transaction data, causing the exchange's own authorization process to approve fraudulent withdrawals across at least five blockchains.

CEO Gracy Chen attributed the attack to actors linked to North Korean state-sponsored hacking operations, citing VPN infrastructure and attack signatures consistent with prior campaigns by the Lazarus Group. The exchange suspended withdrawals immediately and has published a phased resumption schedule beginning September 28. Bitget's 5,500 BTC User Protection Fund, valued at approximately $464 million at time of disclosure, is set to absorb the full loss. Chen stated the company's IPO plans remain intact.

The incident pushes estimated North Korean crypto theft for 2026 past $1 billion and arrives eight days after Bitget published its 45th consecutive monthly proof-of-reserves report showing a 122% reserve ratio.

Table of Contents

  1. Incident Timeline
  2. Attack Mechanics: Spoofed Transfers, Not Stolen Keys
  3. Stolen Asset Breakdown
  4. Laundering Infrastructure
  5. Stablecoin Issuer Response
  6. Exchange Response and Withdrawal Schedule
  7. North Korea Attribution and Context
  8. Economic Value Analysis
  9. Key Takeaways
  10. Conclusion
  11. Sources and References

Incident Timeline

September 16, 2026: Bitget publishes its 45th consecutive monthly proof-of-reserves report, disclosing a 122% reserve ratio across 19 tracked assets. The August 2026 Protection Fund valuation report shows an average monthly value of $382 million.

September 24, 2026, 18:31 UTC: Bitget's internal monitoring systems flag unauthorized transfers from multiple hot wallets. Assets begin moving across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain, Base, and TRON networks.

September 24, 2026, ~20:00 UTC: Bitget suspends all withdrawals. CEO Gracy Chen posts initial disclosure, estimating losses at $351.6 million.

September 25, 2026, 05:00 UTC: Circle blacklists the primary exploiter address. Tether follows shortly after, confirmed by blockchain security firm MistTrack.

September 25, 2026: Chen publishes an updated damage assessment. After accounting for additional Zcash and TRON balances omitted from the initial count, the official total rises to $387.5 million.

September 26, 2026: Bitget announces a phased withdrawal resumption schedule beginning September 28.

Attack Mechanics: Spoofed Transfers, Not Stolen Keys

The Bitget breach differs from prior major exchange hacks in a significant technical detail: no private keys were compromised. According to Bitget and third-party analysis from TRM Labs, the attackers penetrated a backend system connected to the exchange's wallet infrastructure.

Once inside, they manipulated the transaction data presented to Bitget's internal authorization process. The system, designed to verify and approve outgoing transfers, processed the spoofed requests as routine operations. The result was that Bitget's own signing infrastructure authorized the fraudulent withdrawals.

This method — forging internal transaction requests rather than extracting keys — represents a shift from the private-key compromise technique that accounted for 43.8% of total stolen cryptocurrency value in 2024, according to CoinGecko data. It more closely resembles the approach used in the February 2025 Bybit breach ($1.4 billion), where attackers also manipulated internal processes rather than stealing keys directly.

Bitget's cold wallets, which remain offline and isolated from the compromised backend system, were not affected.

Stolen Asset Breakdown

On-chain investigator Lookonchain and TRM Labs published the following breakdown of stolen assets:

| Asset | Amount | Estimated Value (USD) | |-------|--------|----------------------| | XRP | 102.93 million | $157.5 million | | ETH | 31,890 | $85.8 million | | USDT / USDC / USDT0 | — | $75.5 million | | XAUt (tokenized gold) | 3,000 | ~$8.7 million | | BNB | 12,719 | ~$8.5 million | | AVAX | 821,012 | ~$33.0 million | | TRX | 20.59 million | ~$4.6 million | | Other | — | ~$13.9 million | | Total | | ~$387.5 million |

XRP constituted the single largest position at 40.6% of the total haul. ETH was the second-largest at 22.1%.

Laundering Infrastructure

The attacker employed a multi-chain laundering strategy, according to Bitquery and TRM Labs analysis:

Stablecoin conversion: The attacker immediately swapped freezable stablecoins (USDT, USDC) into ETH, which no centralized issuer can freeze or blacklist. This step neutralized the primary countermeasure available to stablecoin issuers.

THORChain routing: Funds on BNB Chain and Ethereum were routed through THORChain, the cross-chain decentralized liquidity protocol, and split across Bitcoin addresses in peel chains — a laundering technique that breaks large sums into progressively smaller transactions across many wallets.

TRON pathway: Stolen TRX was swapped for USDT on SunSwap, moved to Ethereum through the USDT0 bridge, and funneled into the same THORChain route.

THORChain's role in facilitating laundering from major North Korea-attributed hacks has become a recurring pattern. The protocol processed funds from the $1.4 billion Bybit hack in February 2025 and the $292 million KelpDAO bridge exploit earlier in 2026. The protocol's permissionless design makes it structurally resistant to compliance-based intervention.

Stablecoin Issuer Response

Circle and Tether responded within approximately 11 hours of the breach, blacklisting the primary exploiter address labeled "Bitget Exploiter 8." The frozen amount: $318,000 — comprising 218,023 USDT and 99,990 USDC.

The disparity between the $318,000 frozen and the $387.5 million stolen illustrates a structural limitation in the stablecoin freeze mechanism. The attacker converted freezable assets to ETH and other non-freezable tokens within hours. By the time issuers acted, approximately $75 million in stablecoins had already been swapped to ETH, which sits in exploiter wallets totaling more than 63,000 ETH that no issuer can touch.

The freeze captured 0.08% of the total stolen value. As a countermeasure to a $387.5 million theft, this figure speaks for itself.

Exchange Response and Withdrawal Schedule

Bitget's response centered on three pillars:

1. Protection Fund deployment. The exchange's User Protection Fund, backed by 5,500 BTC held in publicly verifiable wallets, is set to cover the full $387.5 million loss. At the time of disclosure, the fund was valued at approximately $464 million. Post-reimbursement, the fund would hold roughly $76.5 million — a drawdown of 83.5%, according to Finance Magnates.

2. Phased withdrawal resumption. Bitget published the following schedule:

| Date | Asset | |------|-------| | September 28, 08:00 UTC | Bitcoin (BTC) | | September 29 | Ethereum (ETH) | | September 30 | USDT | | October 2 | All remaining tokens, fiat, P2P |

3. IPO timeline maintained. Chen stated that Bitget's plan to go public within three years remains unchanged. The company holds more than $1 billion in its own assets, according to its disclosure. Deposits and trading remained operational throughout the incident.

North Korea Attribution and Context

Bitget CEO Gracy Chen stated that investigators identified IP addresses linked to VPN services previously used by North Korean hacking groups. The attack pattern — backend infiltration, transaction spoofing, multi-chain laundering through THORChain — is consistent with prior operations attributed to the DPRK's Reconnaissance General Bureau.

However, attribution remains contested. Some analysts dispute a direct link to the Lazarus Group specifically, even as the broader indicators point to North Korean state actors.

Cumulative DPRK crypto theft context:

| Year | Estimated Theft | Notable Incidents | |------|----------------|-------------------| | 2024 | ~$800 million | WazirX ($234.9M) | | 2025 | $2.02 billion | Bybit ($1.4B) | | 2026 (YTD) | >$1.0 billion | KelpDAO ($292M), Bitget ($387.5M) | | Cumulative (2017–2026) | ~$6.75 billion | — |

According to Hacken and Sanctions.io, North Korean-linked actors have been responsible for over 70% of cryptocurrency exploits in 2026 by value. The regime's cumulative haul since 2017 exceeds $6.75 billion, funds that according to U.S. intelligence assessments are directed toward nuclear weapons research and sanctions evasion.

Economic Value Analysis

The Bitget hack crystallizes several structural questions about how economic value flows through centralized exchange infrastructure:

Protection Fund economics. Bitget's 5,500 BTC Protection Fund represented a form of self-insurance. At $464 million pre-hack, it covered 119.7% of the eventual loss. Post-reimbursement, coverage drops to roughly $76.5 million — insufficient to absorb another incident of similar scale without recapitalization. The fund's dollar value fluctuates with Bitcoin's market price, introducing basis risk: a simultaneous hack-and-BTC-drawdown scenario would compound losses.

Hot wallet attack surface. The breach affected hot and warm wallets — the liquidity layer exchanges maintain for real-time withdrawals. Cold wallets remained intact. The economic tradeoff is clear: hot wallets enable instant withdrawals (a user experience requirement) but expand the attack surface. Bitget's architecture apparently allowed a backend compromise to reach warm wallet layers, suggesting the perimeter between operational infrastructure and signing authority was insufficiently segmented.

Laundering velocity vs. freeze latency. The attacker completed the stablecoin-to-ETH conversion within hours. Issuers froze $318,000 of $75.5 million in stablecoins. The economic implication is that centralized freeze mechanisms are a marginal deterrent when the attacker has a multi-chain laundering playbook and THORChain access. Value leaks faster than counterparties can respond.

2026 hack statistics. Through early August 2026, the industry logged 164 separate incidents — up 69% from 2025's 97 total, according to CoinGecko. Total value stolen in 2026 has reached approximately $3.4 billion, according to Stingrai. The Bitget incident, at $387.5 million, ranks as the year's largest single-exchange breach.

Key Takeaways

  • Bitget lost $387.5 million on September 24 in the largest single crypto exchange hack of 2026. Attackers spoofed internal transaction data rather than stealing private keys.
  • The breach is attributed with moderate confidence to North Korean state-sponsored actors. Cumulative DPRK crypto theft since 2017 now exceeds $6.75 billion.
  • Circle and Tether froze $318,000 of the stolen funds — 0.08% of the total. The attacker converted most stablecoins to non-freezable ETH within hours.
  • Bitget's 5,500 BTC Protection Fund ($464M) covers the loss but will be drawn down to approximately $76.5 million, an 83.5% depletion.
  • Withdrawals resume in phases from September 28 (BTC) through October 2 (all assets). The exchange says its IPO plans are unchanged.
  • THORChain continues to serve as the primary cross-chain laundering conduit for North Korea-attributed hacks.
  • The industry has logged 164 hack incidents through August 2026, up 69% year-over-year. Total 2026 losses stand at approximately $3.4 billion.

Conclusion

The Bitget breach represents the third major exchange hack exceeding $200 million attributed to North Korean actors in the past 18 months, following Bybit ($1.4B, February 2025) and KelpDAO ($292M, April 2026). The attack method — backend compromise and transaction spoofing rather than private key theft — suggests an evolution in technique that renders key management protocols necessary but insufficient.

Bitget's Protection Fund provides a financial buffer, but its 83.5% depletion leaves the exchange materially more exposed to future incidents. The fund's BTC-denominated structure introduces price correlation risk. The phased withdrawal schedule, stretching over eight days, will test user confidence.

The broader pattern is quantifiable. North Korean-linked theft accounts for over 70% of crypto exploit value in 2026. The laundering infrastructure — primarily THORChain — remains functionally intact. Stablecoin freeze mechanisms captured 0.08% of the Bitget haul. The gap between attack velocity and industry response capacity is widening, not narrowing.

For the 120 million users on Bitget's platform, the Protection Fund means their balances remain whole on paper. Whether the exchange can rebuild the fund, restore operational credibility, and proceed toward a public offering will depend on execution over the next 12 months.

Sources and References

  1. Bitget Hack Losses Climb to $387M: Here's What Happened — Decrypt, September 25, 2026
  2. North Korea accused of plundering Bitget for $387 million — Fortune, September 25, 2026
  3. Crypto exchange Bitget says $352 million affected in a hack — CoinDesk, September 24, 2026
  4. Bitget Loses USD 351.6 Million in Hot Wallet Breach — TRM Labs, September 25, 2026
  5. Circle and Tether step in to freeze hacker wallet — CoinDesk, September 25, 2026
  6. Bitget CEO Gracy Chen affirms IPO plans despite breach — Crypto Briefing, September 26, 2026
  7. Bitget Withdrawals Resume September 28: Full Schedule — Crypto Times, September 26, 2026
  8. Bitget Security Breach Costs $387.5M, IPO Plans Intact — Cryptonomist, September 26, 2026
  9. Crypto platform Bitget suspects North Korea in $352 million hack — CNBC, September 25, 2026
  10. North Korea's Crypto Machine in 2026: $6.75 Billion Stolen — Crypto Impact Hub, 2026
  11. Bitget hack: how $352M left, and where it is now — Bitquery, September 2026
  12. Bitget Publishes 45th Consecutive Monthly Proof-of-Reserves Report at 122% Reserve Ratio — Yahoo Finance / Chainwire, September 16, 2026
  13. Crypto Hacking Statistics 2026: $3.4B Stolen — Stingrai, 2026
  14. Crypto Hacks/Exploits Through The Years 2016-2026 — CoinGecko, 2026
  15. Bitget's $388 Million Hack Could Consume 84% of Its Protection Fund — Finance Magnates, September 2026
  16. Bitget Statistics 2026: 120 Million Users, 122% Reserve Ratio — CoinLaw, 2026