North Korean Hackers Very Likely Behind Record $350M Bitget Breach
Bitget detected unauthorized transfers totaling $351.6 million from hot and warm wallets on September 24, 2026, with the breach traced to compromised

Summary
- Bitget detected unauthorized transfers totaling $351.6 million from hot and warm wallets on September 24, 2026, with the breach traced to compromised backend systems rather than stolen private keys.
- CEO Gracy Chen stated that North Korean actors were very likely responsible, following patterns seen in other major 2026 exploits amid a record half-year of crypto losses nearing $1 billion.
- Cold storage remained untouched and customer funds stayed protected, though withdrawals were suspended immediately after the incident as investigations continued.
Alarms went off inside Bitget's monitoring systems at 18:31 UTC on the evening of September 24, 2026. Transfers started draining assets from a limited set of hot and warm wallets in rapid succession. Security teams jumped on emergency protocols within minutes, freezing what they could and launching the forensic review that later pointed away from any classic private-key theft.
That moment marked the largest single crypto theft recorded so far in 2026. Exchange leadership quickly tied the operation to a sophisticated state-linked group rather than an opportunistic exploit or insider leak.
Background on Bitget and Its Security Posture
Bitget launched as a derivatives-focused trading platform and grew into one of the larger centralized exchanges by volume. Its model emphasized high liquidity for perpetual contracts and spot markets while maintaining a tiered custody approach that separated the bulk of user assets in cold storage. This architecture had previously allowed the firm to weather smaller incidents without widespread user impact.
Gracy Chen, who became CEO during the platform's expansion phase, has spoken publicly about the constant pressure exchanges face from advanced persistent threats. In the wake of the September breach she described how attackers gained access to a wallet backend and injected spoofed transaction data, bypassing the need to extract private keys altogether. This method allowed the thieves to initiate and validate withdrawals that appeared legitimate to internal systems.
The approach stood apart from many earlier exchange drains that relied on direct key exfiltration. By focusing on the software layer that orchestrates transfers, the intruders exploited a narrower but still high-value surface. Chen's assessment aligned with intelligence shared across the industry about North Korean groups refining backend intrusion techniques after earlier campaigns. Which, if you've been watching this space, shouldn't be surprising.
The September 24 Incident and Immediate Response
Once the spoofed transfers were identified, Bitget halted all withdrawals and began distinguishing between compromised and untouched addresses. DefiLlama data placed the event at the top of the 2026 loss leaderboard, surpassing other notable exploits that had already pushed first-half totals close to one billion dollars. The exchange confirmed that cold wallets, which hold the majority of assets, were never accessed during the attack window.
Chen reiterated that user funds remained fully backed despite the hot-wallet drain. She noted that the attackers never obtained the underlying private keys, reinforcing the conclusion that the compromise occurred at the application or database layer responsible for transaction formatting and signing requests. This distinction mattered for both technical remediation and insurance or reimbursement planning.
Ongoing analysis has not yet produced definitive on-chain attribution linking specific wallet clusters to known North Korean infrastructure. Investigators continue to examine VPN trails and infrastructure overlaps with prior incidents, but public confirmation remains pending as of the latest statements.
Industry Impact and the Broader 2026 Threat Landscape
The Bitget breach arrived during a period of heightened state-sponsored activity in crypto. Multiple high-profile cases throughout 2026 have already been tied to North Korean operators, contributing to the record pace of losses. Exchanges and custodians have accelerated reviews of backend authorization flows, recognizing that traditional key-management hygiene alone no longer suffices when transaction data itself can be manipulated upstream.
Chen's public comments have prompted other platforms to re-examine similar wallet orchestration services for comparable weaknesses. The incident also underscores the difficulty of rapid attribution in a space where mixing services and cross-chain bridges can obscure trails for weeks or months. While no definitive on-chain proof has surfaced yet, the operational profile matches previously documented campaigns.
"North Korea was very likely behind the $350 million Bitget hack via backend system breach without obtaining private keys."
, Gracy Chen (beincrypto.com)
The scale of the loss has also renewed discussions about reserve transparency and the speed with which exchanges can move assets between hot and cold layers during suspected incidents. Bitget's decision to suspend withdrawals immediately after detection limited further exposure and preserved the integrity of remaining holdings. And honestly, that's a big deal.
Closing the Loop on September 24
Returning to that 18:31 UTC alert, the seconds that followed set in motion a response whose full consequences are still unfolding. The exchange's cold-storage buffers absorbed the shock, shielding the majority of customer balances from the outflow. What began as an urgent internal scramble has evolved into a wider industry conversation about backend integrity and the persistent reach of state-linked actors. As forensic work continues without a final attribution ruling, the $351.6 million figure stands as a stark reminder that even well-architected custody systems remain under sustained pressure in 2026.