North Korean Hackers Blamed as $390 Million Vanishes From Crypto Exchange Bitget
A backend-wallet breach at crypto exchange Bitget ballooned from an initial $351.6 million estimate to roughly $390 million within a day, with the CEO pointing to North Korea's state-linked hacking apparatus in what's now 2026's largest crypto heist.

Crypto exchange Bitget suspended all customer withdrawals Thursday after its security systems flagged unauthorized transfers draining its hot and warm wallets — a breach that started at an initial estimate of $351.6 million and, within a day, had climbed to roughly $387.5 million to $390 million as forensic investigators dug deeper.
Bitget's systems triggered an alert at 18:31 UTC on September 24, and emergency protocols kicked in immediately, the exchange said. By Friday, CEO Gracy Chen was pointing the finger squarely at Pyongyang: \"The attack method in this incident is highly consistent with known patterns of North Korean hacker organizations,\" she said, citing IP addresses tied to VPN services previously linked to DPRK hacking groups.
How the money got out
Rather than stealing private keys outright, attackers are believed to have compromised a critical backend system inside Bitget's wallet infrastructure, using it to spoof transfer data and trick the exchange's own authorization process into releasing funds. Bitget said its offline cold wallets were untouched and that customer balances remain unaffected. Security firms Elliptic and TRM Labs linked the on-chain fingerprint to \"TraderTraitor,\" the same North Korea-linked group blamed for last year's $1.5 billion Bybit hack and the $292 million KelpDAO/LayerZero bridge breach.
THE ATTACK METHOD IN THIS INCIDENT IS HIGHLY CONSISTENT WITH KNOWN PATTERNS OF NORTH KOREAN HACKER ORGANIZATIONS
Bitget says it can cover the losses through its User Protection Fund, which the company claims holds more than $464 million — though that figure hasn't been independently audited. A recovery bounty program is offering 5% of any funds clawed back to whoever helps freeze attacker wallets, and stablecoin issuers Circle and Tether have already frozen $339,100 tied to the attack. Forensics firms Mandiant and SlowMist are conducting third-party investigations, and Bitget has promised a phased plan to resume withdrawals between September 26 and 28.
The heist pushes September's total reported crypto-hack losses above $684 million, according to tracking by CoinDesk — the highest monthly total so far this year, and a fresh reminder that North Korea's hacking units remain the industry's most persistent threat despite years of sanctions and law-enforcement pressure.
What happens next largely depends on how much of the roughly $390 million investigators and exchanges can trace and freeze before it's laundered through mixers and cross-chain bridges — a race that, in past DPRK-linked heists, has recovered only a fraction of stolen funds.