The Bitget North Korea crypto hack is now larger than first disclosed: on-chain tracing has pushed the revised total to $387.5 million, up from the initial $351.6 million figure the exchange announced after discovering the breach, according to BleepingComputer. Bitget’s security systems flagged the first unauthorised transfers at 18:31 UTC on 24 September 2026, according to Tech Insider, triggering a full suspension of withdrawals that remains in place while investigators work through what happened.

The exchange says its cold wallets and the overwhelming majority of platform assets are secure and unaffected. Hot and warm wallets bore the brunt of the attack, and the funds that moved were spread across multiple chains: Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base, with XRP representing the single largest chain-level loss, according to Bitget CEO Gracy Chen.

How the attackers got in

What the exchange knows so far is alarming in its precision. According to Chen, the attacker ‘compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out.’ In other words, whoever was behind this did not simply brute-force a password: they found a way into the signing machinery itself, forging transfer information that the platform’s own authorisation process then approved.

Bitget has not yet confirmed how the attackers initially accessed that backend wallet-service system, and the company says the specific method of intrusion remains under active investigation. What it does say is that no further unauthorised transfers are possible.

The North Korea attribution rests on two pillars. First, on-chain analysis shows attack patterns that Chen described as ‘highly consistent with known patterns of North Korean hacker organizations.’ Second, and more concretely, investigators identified internet protocol addresses linked to VPN services previously used by a North Korean hacking group, according to CNBC. Some chains have also confirmed that the hacker wallet addresses have been frozen since the attack. Bitget says it has reported the incident to relevant institutions and is cooperating in a global investigation.

The Bitget North Korea crypto hack in the wider 2026 picture

Put this in context and the scale becomes harder to shrug off. Data from DefiLlama, cited by Yahoo Finance, ranks the Bitget theft as the largest crypto hack of 2026 so far, accounting for roughly 16% of the approximately $2.2 billion lost across 281 incidents this year. One exchange, one night, one-sixth of the year’s total losses across the entire industry.

It also invites an uncomfortable comparison with the Bybit heist, in which North Korean hackers stole $1.5 billion from that exchange’s ETH cold wallet. The Bitget North Korea crypto hack is a smaller absolute figure than Bybit, but its spread across hot and warm wallets on seven separate chains makes it a different kind of operation: broader, more distributed, and apparently designed to extract value from multiple assets simultaneously, including ETH, XRP, BNB, AVAX, USDT, USDC, and other tokens.

What Bitget is telling customers

Bitget is leaning heavily on its User Protection Fund to reassure users. The fund currently holds 5,500 BTC, worth approximately $464 million, and the company says the incident falls within its coverage. Customer account balances remain accurate, and deposits and trading continue to operate normally, the exchange said. The self-custodial Bitget Wallet was not affected, as it operates on infrastructure independent of Bitget Exchange.

Withdrawals, however, remain suspended. Bitget says it will restore them as soon as investigators confirm it is safe to resume normal operations. The exchange is working with law enforcement agencies, on-chain security institutions, and cybersecurity experts at Mandiant and SlowMist. Chen’s message to customers was blunt: ‘No further unauthorized transfers are possible.’

Whether that reassurance holds will depend on how thoroughly investigators can establish what the attacker actually touched inside the backend infrastructure. With the revised loss figure already climbing from $351.6 million to $387.5 million as on-chain tracing continues, the final tally may not yet be settled.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version