Skip to content

From the FinCrime Agent course

Want to do this for a living?

This is the kind of story financial-crime professionals act on every day. Learn the craft in Marco’s AML & Financial Crime course.

AML & Financial Crime course →
Back to Issue №18

Bitget discloses $351.6m hack, updates loss to $390m, points to North Korea

Suspected North Korean hackers moved crypto out of Bitget's hot and warm wallets on September 24, with the confirmed figure later revised upward.

Source CNBC
Act now Crypto Cybercrime Global

What happened

Bitget disclosed a breach that occurred on September 24, 2026 at 18:31 UTC. The exchange initially reported $351.6 million stolen. It later updated the figure to approximately $390.06 million in assets moved to attacker controlled addresses.

Only Bitget’s hot and warm wallets were affected. Cold wallets remained secure, according to the exchange. Stolen assets included ETH, XRP, BNB, AVAX, USDT, and USDC, spread across the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base networks.

Bitget said attackers “compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out.” Roughly $183 million of the stolen funds was swapped for Ether tokens. Bitget suspended withdrawals temporarily, brought in Mandiant and SlowMist for a third party investigation, and resumed withdrawals in phases on September 28, 2026.

Circle and Tether froze $339,100 in stablecoins linked to the hack. Bitget said its User Protection Fund, which holds over $464 million, covers the full amount of the loss.

Why it matters

The North Korea attribution rests on IP behavior patterns and on chain analysis that investigators say match known North Korean hacker patterns, per Bitget and the investigators involved. This is an attribution claim, not a court finding, and it should be read that way even though it lines up with independent blockchain analytics.

Elliptic identified connections between the stolen Bitget funds and addresses tied to laundering from earlier DPRK attributed exploits, including the 2025 Bybit theft of $1.5 billion. TRM Labs separately confirmed overlaps with wallets used in the Bybit and AFX Bridge laundering operations, pointing to the threat actor group known as TraderTraitor. Two independent analytics firms converging on the same laundering infrastructure strengthens the case that this is a repeat operation rather than an isolated incident, though the underlying compromise vector, a spoofed backend authorization process, is a mechanism the industry keeps seeing across separate victims.

Elliptic’s figure putting North Korea’s cumulative 2026 crypto theft above $1 billion suggests this money laundering pipeline through DeFi swaps and exchange linked wallets is functioning at a sustained, industrial scale rather than as one off opportunism.

Practitioner angle

Exchanges, custodians, and any virtual asset service provider (VASP) with hot or warm wallet exposure should treat this as a live control failure case study, not a headline to skim.

  • Review backend authorization workflows for wallet infrastructure: specifically, whether transaction data can be spoofed before it reaches the signing or authorization layer, and whether that layer independently verifies transaction integrity rather than trusting upstream data.
  • Check exposure to the addresses and laundering infrastructure TRM Labs and Elliptic have linked to TraderTraitor and prior DPRK attributed thefts (Bybit, AFX Bridge). Screen transaction monitoring rules and wallet screening lists against these disclosed clusters now.
  • Reassess hot and warm wallet balance limits and withdrawal thresholds. Bitget’s cold wallets held, which is the control that worked here.
  • If your institution holds a User Protection Fund or equivalent reserve, verify it is sized and liquid enough to cover a hot wallet scale loss without disrupting customer withdrawals.
  • Flag any inbound stablecoin or crypto flows traced to this incident for enhanced due diligence, and coordinate with Circle or Tether on freeze requests if exposure is identified.

The single most important action this quarter: audit whether your wallet infrastructure’s authorization step can be triggered by spoofed transaction data, since that is the specific mechanism Bitget says was exploited.

Share:

Want to do this for a living?

Turn this weekly intelligence into a career. Marco’s AML & Financial Crime course takes you from curious to hireable.

AML & Financial Crime course →