Cryptelio

Hacks & Exploits

Bitget Hack Attributed to North Korean Hackers, $387 Million Stolen

Cryptelio Editorial Published 3 Oct 2026 · 17:31 UTC

Bitget, a cryptocurrency exchange, has reported a major security breach resulting in the theft of approximately $387 million. Chainalysis has linked this incident to North Korean hackers, marking a troubling trend as the total value of crypto stolen by DPRK-affiliated actors in 2026 surpasses $1 billion.

The hack occurred on September 24, 2026, exploiting a zero-day vulnerability in third-party security software that allowed attackers to gain high-level credentials and issue fraudulent withdrawal commands. The breach affected Bitget's hot and warm wallets, while cold wallets remained secure. Following the attack, Bitget suspended withdrawals but began restoring them on September 28, assuring users that losses would be covered by its User Protection Fund, which had a value exceeding $464 million prior to the incident.

In a notable twist, the attackers utilized a cross-chain swap to convert stolen XRP into Bitcoin, avoiding exchanges to obscure their tracks. Chainalysis reported that within the first three hours post-breach, $387 million was distributed across four blockchains, with Ethereum receiving nearly half of the outflows.

Bitget's CEO, Gracy Chen, had indicated a North Korean connection shortly after the breach, citing IP addresses associated with DPRK VPNs. This hack is now recognized as the largest crypto theft of 2026, significantly increasing September's overall losses by 462%.

In response to the hack, Bitget has criticized parts of the DeFi ecosystem for their reluctance to assist in recovering stolen funds. However, the NEAR Intents protocol successfully identified and halted over $50 million in illicit laundering attempts related to the breach, although actual recoveries were minimal.

FAQ

What happened during the Bitget hack?

Bitget experienced a major security breach on September 24, 2026, resulting in the theft of approximately $387 million. The hack exploited a zero-day vulnerability in third-party security software, allowing attackers to gain high-level credentials and issue fraudulent withdrawal commands.

Who is believed to be behind the Bitget hack?

Chainalysis has linked the Bitget hack to North Korean hackers, marking a concerning trend as the total value of cryptocurrency stolen by DPRK-affiliated actors in 2026 has surpassed $1 billion.

What measures did Bitget take following the hack?

After the breach, Bitget suspended withdrawals but began restoring them on September 28. The exchange assured users that losses would be covered by its User Protection Fund, which had a value exceeding $464 million prior to the incident.

How did the attackers convert the stolen funds?

The attackers used a cross-chain swap to convert the stolen XRP into Bitcoin, avoiding exchanges to obscure their tracks. Within the first three hours post-breach, $387 million was distributed across four blockchains, with Ethereum receiving nearly half of the outflows.

What has been the response from the DeFi ecosystem regarding the hack?

Bitget criticized parts of the DeFi ecosystem for their reluctance to assist in recovering stolen funds. However, the NEAR Intents protocol successfully identified and halted over $50 million in illicit laundering attempts related to the breach, although actual recoveries were minimal.

Read story →