Cryptocurrency platform Bitget has reported a significant security breach resulting in the theft of $351.6 million. The theft is believed to have been executed by hackers linked to North Korea, affecting the platform’s hot and warm wallets.
Incident Overview
The unauthorized transactions were detected at 18:31 UTC on September 24, 2026, as per Bitget’s announcement on X. Although the breach impacted a limited number of wallets, the company’s cold wallets and most of its assets remain secure. Bitget has reassured users that account balances are correct, and the platform’s trading and deposit functions are operating as usual. However, withdrawals have been paused to conduct a detailed security review.
Investigation Underway
While Bitget has not disclosed the specifics of the breach, it has enlisted the expertise of Mandiant, a Google subsidiary, and SlowMist for a comprehensive third-party investigation. It clarified that the Bitget Wallet, operating independently from the Bitget Exchange, was not compromised.
CEO Gracy Chen highlighted that the stolen assets included cryptocurrencies such as ETH, XRP, BNB, AVAX, USDT, and USDC, involving multiple blockchain networks like Ethereum and Avalanche. The foundations of these networks have been contacted, with some already taking steps to freeze the illicit wallet addresses.
Method and Consequences
The attack involved compromising a critical backend system used to manipulate transaction data, subsequently triggering the authorization process for fund transfers. The attack methodology aligns with patterns known to be used by North Korean hacker groups, specifically targeting infrastructure to spoof data and authorize unauthorized transactions.
This incident follows a recent attack attributed to the North Korea-linked TraderTraitor group, which targeted an IT services company in India. The group is notorious for substantial cryptocurrency thefts, including $1.5 billion from Bybit.
Future Outlook
Bitget’s response to this breach emphasizes the critical need for robust cybersecurity measures within cryptocurrency exchanges. As the investigation continues, Bitget aims to enhance its security protocols to prevent future incidents. The collaboration with Mandiant and SlowMist underscores the importance of expert involvement in addressing complex cyber threats.
