Chainalysis linked the 24 September breach to North Korea-linked hackers, taking their 2026 crypto theft past $1B. For the next few weeks, every exchange security claim will be read against this case.
Between 18:31 and 21:23 UTC on 24 September, $387.5M left Bitget’s hot and warm wallets.
Nobody stole a key. The attackers fed forged transfer data into Bitget’s backend, and Bitget’s own signing process approved the payouts.
On 1 October, Chainalysis published its tracing work and attributed the attack to actors linked to the Democratic People’s Republic of Korea (DPRK). It’s the largest crypto hack of 2026 so far.
How the attackers got in
The entry point was outside Bitget’s own code. Attackers used a zero-day in one of 2 third-party security products connected to Bitget’s systems. The earliest malicious activity traces back to 31 August, so they had at least 24 days inside before moving any money.
With internal credentials in hand, they used custom tools to get past risk controls and push withdrawals that looked routine.
CEO Gracy Chen explained it during a livestream on X: “They did not forge user withdrawal requests, nor did they obtain our private keys.”
The number grew as Bitget counted. About $183M within the first hour. Then $351.6M. By 25 September, the final figure was $387.5M.
The single biggest piece was roughly 103M XRP, worth about $157M at the time. The rest was mostly ETH and stablecoins, spread over several chains.
How Chainalysis traced the money
In the first 3 hours, the stolen funds moved through 23 transfers onto 4 blockchains:
- Ethereum: 49.7%
- XRP Ledger: 40.8%
- Zcash: 7.6%
- Tron: 1.8%
From there the attackers ran the funds through cross-chain liquidity protocols, messaging protocols, instant swap services and laundering services. The XRP was converted into Bitcoin over about 36 hours before landing in attacker-controlled Bitcoin addresses.
Chainalysis says its in-house AI cut “more than 20 hours of manual bridge reconciliation” down to under 10 minutes. Human investigators still set the logic and checked the results.
The attribution doesn’t rest on Chainalysis alone. Elliptic called a North Korea connection “highly likely.” Chen pointed to VPN patterns and on-chain behaviour that matched earlier DPRK attacks.
Recovery looks thin. Circle and Tether froze about $318,000 in stablecoins. With NEAR Intents added, the total frozen is around $1.1M, less than 0.3% of what was taken. Chen has said she expects little to come back.
North Korea’s crypto year so far
With Bitget, DPRK-linked theft in 2026 is now above $1B, according to Chainalysis.
For scale, the same groups took a record $2B in 2025. Most of that came from one event, the $1.5B Bybit hack in February 2025, which the FBI attributed to North Korea.
The pattern repeats. Large centralised exchanges hold big hot wallets, and the attackers go after the systems around those wallets: signing flows, approval tools, vendor software and the people with access.
What Bitget did for users
User balances weren’t touched. Bitget covered the loss through its User Protection Fund, which it valued at over $464M before the hack, plus company capital.
Trading and deposits kept running. Withdrawals were paused at 18:31 UTC on 24 September and reopened in stages from 28 September, starting with Bitcoin.
Bitget’s token BGB fell nearly 7% to $1.93 after the news, then recovered slightly to $1.97.
The fixes Bitget has listed so far:
- Multiple approvals for critical operations
- All internal credentials revoked and sensitive system access restructured
- The affected vendor feature switched off
- Stricter checks on withdrawal verification
It also brought in Mandiant and SlowMist to investigate and offered a recovery bounty of up to 5%.
What exchanges will be asked next
“Funds are safe” is the standard line after any exchange incident. Bitget could say it because the protection fund was big enough to absorb a loss this size. Not every exchange has a fund that large.
Expect users and partners to ask every exchange harder questions for a while:
- Which third-party tools sit inside your withdrawal path, and who can approve a transfer?
- How big is your protection fund, and could it cover a loss of $300M+?
- How fast would you disclose a breach, and would you update the number publicly as it changes?
- What did you change after the last incident, in plain words?
Proof of reserves shows balances on a given day. It says nothing about whether a forged request can get through the approval system. After Bitget, that’s the gap people will look at.
Disclosure speed counts too. Chen went live on X for 3 hours and updated the loss figure as it grew. Exchanges that stay quiet for a day after an incident will be compared against that.
What we still don’t know
Bitget hasn’t named the 2 third-party security products involved. Its full security report isn’t out yet.
That matters for every exchange using similar vendors. Until the names are public, nobody can say for sure whether the same flaw sits inside other platforms.
If your exchange’s security page was written before 24 September, does it say anything about the vendors in your withdrawal path?
