Skip to content
Security & Trust

North Korea-Linked Hackers Steal $387 Million From Bitget

CEO says a backend wallet system was breached; a $464M reserve fund will cover client losses

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
North Korea-Linked Hackers Steal $387 Million From Bitget

Photo: cottonbro studio / Pexels

Key finding

Confirmed loss: $387.5 million (Source: The Record, citing Bitget CEO Gracy Chen (Sept 28, 2026))

A Backend System, Not a Front End, Failed

Singapore-based crypto exchange Bitget lost more than $387 million after attackers breached a backend system tied to its wallet services, according to comments CEO Gracy Chen made during a company town hall reported by The Record on September 28, 2026. Chen said the intrusion exploited vulnerabilities in that backend infrastructure to push through unauthorized transfers of ether, XRP, USDC and other tokens. Security teams caught the anomaly in progress and triggered emergency protocols, but not before losses climbed past initial estimates near $175 million to a confirmed figure of $387.5 million.

$387.5 million
Confirmed loss
Source: The Record, citing Bitget CEO Gracy Chen (Sept 28, 2026)

A Threat Pattern Investigators Recognize

Chen told employees that IP addresses, behavioral patterns and on-chain transaction signatures pointed to hacking groups linked to North Korea, a conclusion blockchain investigators reached independently as they traced the stolen funds. Bitget has notified law enforcement and is working with incident-response firms Mandiant and SlowMist while withdrawals remain suspended. The attribution fits a pattern documented well beyond this single incident: United Nations investigators found North Korea generated more than $3 billion from cryptocurrency platform attacks between 2017 and 2023, and separately determined the country stole more than $2 billion through similar operations last year alone.

$2 billion+
North Korea's crypto theft, prior year
Source: United Nations investigators, cited by The Record (Sept 28, 2026)

Bitget Is Not the First Exchange to Face This

Chen invoked the closest precedent directly: Dubai-based Bybit's $1.5 billion loss to North Korean hackers last year, an incident the exchange survived. "If Bybit can hold on after a $1.5 billion loss, we can definitely hold on to a $350 million-plus loss," Chen said, adding that Bitget would work through recovery the way Bybit managed its own bank run and liquidity crunch. Earlier in 2026, North Korea-linked actors were also tied to $280 million taken from the Kelp platform and $290 million from Drift, both cases involving fabricated companies and fake personas used to gain trusted access.

$1.5 billion
Bybit precedent cited by Chen
Source: The Record, citing Bitget CEO Gracy Chen (Sept 28, 2026)

The Reserve Fund Covering the Gap

Bitget said its User Protection Fund holds more than $464 million and will be used to make affected customers whole, a buffer that exceeds the confirmed loss by roughly $77 million. The company also opened a recovery bounty: platforms that voluntarily freeze attacker-linked wallets earn 5% of the frozen amount, with another 5% paid if funds are ultimately recovered. Several exchanges have already frozen a portion of the stolen assets, according to Chen.

$464 million
User Protection Fund balance
Source: The Record, citing Bitget CEO Gracy Chen (Sept 28, 2026)

Questions for Your Team

Bitget frames this as a backend infrastructure compromise, not a smart-contract or front-end failure, a distinction budget-holders overseeing any crypto custody, payments or treasury exposure should press their own vendors on. Ask which backend systems handle wallet transfers and what monitoring flags anomalous transfer patterns in real time. Ask whether any vendor holding company funds maintains a loss-absorbing reserve, and whether its size and liquidity are independently verified rather than self-reported. Ask what the contractual and operational plan is if a custodian suspends withdrawals, and how that maps to your own liquidity needs. Given the recurrence of North Korea-linked intrusions across Bybit, Kelp, Drift and now Bitget, ask whether incident response planning includes coordination with other platforms and law enforcement before an incident occurs, not only after.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: The Record.

Share this insight