Bitget's $387.5 Million Hack: On-Chain Clues Point to a Possible North Korea Link

Bitget $387.5 million hack and suspected North Korea crypto attack


The short version: Bitget says approximately $387.5 million in crypto was transferred to attacker-controlled addresses during a September 24 security incident. The exchange initially estimated the loss at $351.6 million, but later revised the figure after identifying additional Zcash and TRON-related transfers. Bitget says the underlying vulnerability has been fixed, while an investigation involving Mandiant and SlowMist is continuing.

The incident has also raised a possible North Korea connection. Bitget CEO Gracy Chen said investigators found IP addresses that appeared to match VPN infrastructure associated with a DPRK-linked hacking group. Separate on-chain analysis has also drawn attention to links between some of the stolen funds and wallets associated with earlier attacks attributed to North Korean operators.

That does not make the attribution final. No public government investigation has, at the time of writing, formally established that Lazarus or another named North Korean unit carried out the Bitget attack.

What Happened to Bitget?

Bitget's security systems detected unauthorized transfers from parts of its hot-wallet infrastructure at approximately 18:31 UTC on September 24, 2026.

The exchange immediately activated its incident-response procedures and suspended withdrawals as a precaution. Deposits and trading remained available, while Bitget said customer account balances were accurate.

The first estimate put the affected assets at approximately $351.6 million. Bitget later revised the figure to approximately $387.5 million after its tracing work identified additional assets, including Zcash and TRON-related transfers.

The revised figure does not necessarily mean another $35.9 million was stolen after the initial incident. It reflects a broader accounting of the transfers connected to the September 24 event.

Bitget has said its cold wallets were not affected. The exchange also said its investigation did not indicate a conventional private-key theft. Instead, the suspected attack path involved its wallet infrastructure and authorization process.

The Attack Was Not a Simple Private-Key Theft

That distinction is important.

In a traditional crypto exchange breach, an attacker may obtain private keys or gain direct control of wallets and then sign transactions. Bitget's preliminary explanation points to a different type of failure.

According to the exchange, the attacker compromised a critical backend component within the wallet infrastructure, manipulated transaction information and caused the authorization process to approve transfers that should not have been approved.

In other words, the security problem appears to have been somewhere between the exchange's internal systems and the final wallet authorization process rather than a straightforward theft of cold-wallet private keys.

Bitget says the vulnerability has now been identified and remediated. Cybersecurity company Mandiant and blockchain security firm SlowMist are assisting with the investigation.

XRP Became One of the Biggest Pieces of the Theft

On-chain trackers identified approximately 102.93 million XRP among the assets associated with the attack, worth roughly $157 million at the prices used in early reporting.

Other identified assets included ETH, USDT, USDC, USDT0, tokenized gold, BNB, AVAX and TRX. The final composition of the stolen assets can change as blockchain investigators continue to classify addresses and transactions.

One transaction that attracted particular attention involved approximately 19.67 million USDT0 being exchanged for around 7,111 ETH within minutes. Reports said the attacker paid a significant premium for the ETH.

Paying above-market prices can be consistent with an attacker prioritizing speed over execution efficiency. But the transaction itself does not prove the attacker's motive. In a rapidly developing investigation, that distinction matters.

Why Investigators Are Looking at North Korea

The North Korea connection comes from several separate pieces of evidence rather than one definitive fingerprint.

Bitget CEO Gracy Chen said investigators identified IP addresses that matched VPN choices associated with a DPRK-linked hacking group. Chen described the North Korea connection as highly likely, while acknowledging that the investigation was still developing.

That is an important distinction: Bitget suspects North Korean involvement, but suspicion is not the same as a completed attribution.

On-chain investigators have provided another reason for the suspicion. Blockchain researcher Specter and other analysts have examined the movement of stolen XRP and other assets and reported links with wallet clusters associated with previous attacks.

Some of those addresses have connections to earlier thefts attributed to North Korean operators. The similarities have strengthened the hypothesis that the same broader ecosystem may be involved.

However, wallet overlap alone does not establish who physically conducted an attack. Crypto thieves frequently use intermediaries, laundering services, bridges and previously compromised addresses. Attribution therefore requires combining blockchain evidence with off-chain information such as infrastructure, IP data, malware, operational patterns and law-enforcement intelligence.

The Lazarus Question

The word Lazarus has appeared repeatedly in discussions around the Bitget incident because North Korean-linked hacking groups have been associated with some of the largest cryptocurrency thefts in recent years.

The FBI previously attributed the $1.5 billion Bybit theft to North Korea and identified the activity as part of the TraderTraitor campaign. Other North Korean-linked operations have also targeted exchanges, DeFi projects and cryptocurrency companies.

But the Bitget case should not yet be written as a confirmed Lazarus operation.

The evidence currently available supports a more careful description: Bitget and blockchain investigators see indicators consistent with previous DPRK-linked activity, while the final attribution remains under investigation.

That wording is less dramatic than simply calling the attacker Lazarus, but it is also more accurate.

Bitget's Protection Fund Is Larger Than the Reported Loss

One of the immediate questions for customers was whether the exchange had enough reserves to absorb the incident.

Bitget says its User Protection Fund holds more than 5,500 BTC. When the incident was first announced, the exchange valued the fund at more than $464 million.

That figure was above the initial $351.6 million estimate and remains above the later $387.5 million figure based on the valuations Bitget reported. Because the protection fund is largely denominated in BTC, however, its dollar value changes with the Bitcoin market.

Bitget has repeatedly said customer account balances were not reduced by the incident and that the protection fund is intended to cover the financial impact.

When Will Bitget Withdrawals Resume?

The withdrawal freeze was one of the biggest operational consequences of the attack.

Bitget has now announced a phased restoration rather than reopening every withdrawal service at once.

Date and time (UTC) Withdrawal service
September 28, 08:00 BTC on the Bitcoin network
September 29, 08:00 ETH on Ethereum, BNB Smart
Chain, Arbitrum, Base and Optimism
September 30, 08:00 USDT on Ethereum, BNB Smart
Chain, Solana and Tron
October 2, 08:00 Other tokens, fiat services and
P2P withdrawals

The staged schedule is significant because it shows Bitget is treating the incident as a wallet-infrastructure problem rather than simply turning withdrawals back on after patching one component.

The exchange says additional security checks are being completed before each stage is restored.

A 5% Recovery Bounty Has Also Been Announced

Bitget has launched a recovery program aimed at entities that can help freeze or recover stolen assets.

The exchange announced a 5% bounty for voluntarily freezing attacker-controlled funds and another recovery incentive under its bounty framework. Bitget is also working with blockchain security specialists to trace the stolen assets across chains.

This matters because much of the stolen cryptocurrency has already moved through multiple wallets and networks. Once assets are converted into assets that cannot be frozen by an issuer, recovery becomes considerably harder.

Why the Bitget Hack Matters

The size of the incident makes it significant on its own. The approximately $387.5 million figure places the Bitget breach among the largest cryptocurrency thefts of 2026.

But the more important lesson may be the attack surface.

Crypto exchanges have spent years improving cold-wallet security, multisignature controls and key-management procedures. Yet an exchange can still face a major loss if an attacker finds a way to manipulate the systems that decide which transactions should be authorized.

That changes the security question from "Can someone steal the private key?" to "Can someone make the system authorize a transaction that should never have been approved?"

For large exchanges, that distinction is becoming increasingly important.

The Bigger North Korean Crypto-Theft Pattern

North Korean-linked cyber operations have become a recurring concern for the cryptocurrency industry. Blockchain analytics companies and governments have attributed billions of dollars in digital-asset thefts to DPRK-linked actors over the years.

The Bybit attack in 2025, along with other exchange and DeFi incidents, showed how these groups can combine social engineering, compromised infrastructure, wallet manipulation and sophisticated laundering techniques.

If the Bitget attribution is ultimately confirmed, it would add another major exchange infrastructure incident to that record.

For now, however, the evidence should be described as a developing attribution rather than a settled conclusion.

What Happens Next?

The next major milestone is Bitget's phased withdrawal restoration beginning September 28.

At the same time, investigators will continue following the stolen assets and examining how the attacker entered and moved through Bitget's wallet infrastructure.

The final forensic report should answer several questions that remain open: exactly which backend component was compromised, how the attacker bypassed existing controls, how authorization was manipulated, how much of the stolen cryptocurrency can still be traced, and whether the suspected DPRK connection can be independently confirmed.

The Bottom Line

Bitget's September 24 breach is no longer a story about an exchange losing an initially estimated $351.6 million. The latest figure is approximately $387.5 million, after additional assets were identified.

The more interesting part of the case is what happened behind the wallets.

Bitget says its private keys were not stolen and that the attack instead exploited weaknesses in its wallet infrastructure and authorization process. On-chain investigators have traced portions of the stolen funds across multiple networks, while Bitget's CEO has pointed to indicators suggesting possible DPRK involvement.

Those clues deserve attention, but the final attribution still matters. Until investigators publish enough evidence to establish who controlled the infrastructure and carried out the operation, the most accurate description is a suspected North Korea-linked attack, not a confirmed Lazarus operation.

For Bitget customers, the immediate question is more practical: withdrawals are scheduled to return in stages beginning September 28, while the exchange and its outside investigators continue working through the forensic investigation and recovery effort.

The Bitget incident shows that in modern crypto security, the private key is only one part of the problem. The systems surrounding that key can be just as important.

Sources

  • Bitget official security incident updates
  • Bitget withdrawal restoration update
  • On-chain analysis from blockchain researchers and security firms
  • Reporting on Bitget's preliminary North Korea attribution

Post a Comment

0 Comments