Initial theft reported from hot and warm wallets: $351.6M (Source: Bitget statement, reported by The Hacker News (September 27, 2026))
What Bitget has disclosed
Cryptocurrency exchange Bitget said suspected North Korean threat actors stole $351.6 million from its hot and warm wallets, as reported by The Hacker News. In a post on X, Bitget said its security systems identified unauthorized transfers at 18:31 UTC on September 24, 2026. The company said its cold wallets and the overwhelming majority of platform assets were unaffected, and that customer account balances remain accurate.
The initial figure has since risen. In a follow-up post on X, Bitget cited its latest on-chain tracing and classification of transactions and said assets equivalent to approximately $390.06 million were transferred to attacker-controlled addresses across multiple networks.
For any organisation that authorises payments, the mechanism matters more than the total. CEO Gracy Chen said the attacker compromised a critical backend system within the wallet infrastructure, used it to spoof transaction data, and triggered the exchange's authorization process to move funds out. Chen's description implies the authorization process acted on falsified data. Bitget has not said whether the process itself functioned as intended. It has said the vulnerability involved has been identified and addressed. It has not disclosed how the intrusion occurred, and said the method remains under active investigation.
Scope, attribution and response
The affected assets include ETH, XRP, BNB, AVAX, USDT and USDC, across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base, according to Chen. Bitget says Bitget Wallet, a self-custodial product on separate infrastructure from the exchange, was not affected.
Attribution rests on Bitget and outside analytics firms, not on a confirmed finding. Chen said IP behavior patterns and on-chain analysis are highly consistent with known North Korean groups. Elliptic reported connections between stolen Bitget funds and addresses used to launder earlier DPRK-attributed exploits, including the 2025 Bybit theft. TRM Labs found overlaps with wallets used to launder the Bybit and AFX Bridge proceeds and said they point to the TraderTraitor group. The Hacker News noted TraderTraitor is best known for the $1.5 billion Bybit theft and the $292 million KelpDAO LayerZero bridge theft.
Bitget has engaged Mandiant and SlowMist for a third-party investigation and contacted the foundations of affected chains. Some have confirmed freezing hacker wallet addresses. It has also launched a Recovery Bounty Program. Withdrawals were suspended and are due to resume in phases from September 28, 2026 at 8 a.m. UTC.
What a budget-holder should ask their team
Bitget's account describes falsified data flowing from a compromised internal system into its approval process. How the attacker got in has not been disclosed. The questions below apply to any organisation that moves money or grants access through automated approvals.
First, does our authorization process verify transaction details independently of the backend system that supplies them, or does it accept upstream data as given? Second, which internal systems can write to the data our approvers rely on, and who has tested what happens if one of them is compromised? Third, what limits apply to funds held in operationally accessible accounts, compared with those held under stricter controls? Bitget's cold wallets were reported unaffected. Fourth, do we have an incident retainer and a tested plan for suspending outbound transfers while a review runs? Bitget paused withdrawals during its investigation. Finally, which of our payment and identity systems are separated from each other, and has that separation been tested rather than assumed?
The intrusion method is not yet public. These questions do not depend on it.





