Bitget Hack Losses Climb to $387M: Here’s What Happened, and Why North Korea Is a Suspect

Bitget disclosed a $387.5 million breach discovered on September 24 after attackers used forged internal transfer requests to move funds from the exchange's hot and warm wallets rather than by stealing private keys. The haul included about 103 million XRP (roughly $157 million), and CEO Gracy Chen said IP and on‑chain indicators resemble techniques linked to North Korean state‑linked hacking groups.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished 39 minutes agoUpdated 39 minutes ago0 views
Bitget Hack Losses Climb to $387M: Here’s What Happened, and Why North Korea Is a Suspect

Why It Matters

The incident is one of the largest crypto exchange breaches this year and highlights risks from attacks that manipulate internal authorization systems rather than breaking cryptographic keys. Bitget's pledge to cover losses from its User Protection Fund and the involvement of forensic firms and law enforcement underscore the systemic and regulatory implications for centralized exchanges.

Key Facts

  • Date detected: September 24, 2026 (18:31 UTC detection of unauthorized transfers)
  • Total loss: $387.5 million (updated tally)
  • XRP portion: Approximately 103 million XRP, about $157 million
  • Initial on-chain tally within an hour: About $183 million in stablecoins, Ethereum and other assets
  • Earlier public figure same day: $351.6 million (hours after initial detection)

Bitget confirmed a security breach that led to $387.5 million in cryptocurrency leaving wallets it operates. The exchange said attackers did not obtain cold‑wallet private keys or forge user withdrawal requests; instead, the adversary compromised a backend component of Bitget's wallet infrastructure and spoofed transaction data to gain approvals that appeared legitimate. Blockchain investigators observed rapid asset movements starting at 18:31 UTC on September 24, with an early on‑chain count showing about $183 million leaving wallets tied to the exchange. Additional outflows across at least five blockchains were later linked to the same attacker‑controlled addresses; the largest single asset taken was roughly 103 million XRP, valued at about $157 million. Bitget CEO Gracy Chen said the exchange engaged forensic firms including Mandiant and SlowMist and reported the incident to law enforcement. Chen indicated that IP addresses and on‑chain behavior seen in the operation resemble methods previously attributed to North Korean state‑linked groups, but she cautioned that attribution is not yet confirmed and technical evidence has not been publicly released. The exchange said the outflows have been halted and that withdrawals were paused as a precaution while deposits and trading continued. Bitget will use its User Protection Fund — which it says holds more than $464 million — to cover the loss so customer account balances are preserved. The company has promised a full incident report and root‑cause analysis once remediation and investigations are complete.

Keep Reading