VYPR
breachPublished Sep 25, 2026· 1 source

North Korea Linked to $387.5M Heist from Crypto Exchange Bitget

Crypto exchange Bitget has attributed a massive $387.5 million theft to North Korean state-sponsored actors, exploiting a backend system of its wallet service.

Crypto exchange Bitget has confirmed that a cyberattack, exhibiting characteristics strongly indicative of North Korean state-sponsored operations, resulted in the theft of approximately $387.5 million in digital assets. The exchange initially estimated the loss at $351.6 million but later revised the figure upwards after identifying additional affected assets across Zcash and TRON networks. Blockchain intelligence firm Arkham observed that a significant portion of the funds, around $228 million, was transferred out of Bitget's wallets within an 18-minute window.

The stolen assets included substantial amounts of ETH, USDT, USDC, and Tether Gold, spread across multiple blockchain networks such as Ethereum, Arbitrum, Optimism, BNB Smart Chain, Avalanche, and Base. However, Bitget's CEO, Crystal Chen, assured users that the exchange's cold wallets and customer balances remain unaffected. She emphasized that Bitget's User Protection Fund, valued at over $464 million, is sufficient to cover the losses, and the company holds an additional $1 billion in its own assets, ensuring user funds are covered on a 1:1 basis.

Bitget's self-custody product, Bitget Wallet, operates on separate infrastructure from the exchange, and normal trading operations continue, although withdrawals were temporarily suspended for enhanced security checks. The exchange has enlisted the services of incident response firm Mandiant and blockchain security company SlowMist to aid in the investigation.

According to Chen, the attackers breached a key backend system of the wallet service, exploiting it to forge transfer information and initiate unauthorized withdrawals. The investigation has ruled out private key leakage, indicating a more severe but contained risk scenario. While the specific intrusion methods are still under technical review, initial analysis of "IP behavioral patterns and on-chain signatures" points towards North Korean state-sponsored actors.

This incident aligns with a pattern of cryptocurrency heists attributed to North Korea, which has a documented history of targeting exchanges to fund its regime. Previous major attacks linked to the nation include a significant breach at Bybit earlier in 2025, as well as incidents involving DMM Bitcoin and WazirX.

Bitget, founded in 2018 and registered in the Seychelles, operates globally. The timing of the breach, with transfers detected during the Mid-Autumn Festival holiday in China and Singapore, has raised speculation about potential exploitation of reduced operational capacity during the holiday period, though Bitget has not commented on this.

In response to the attack, Bitget is offering a bounty of 5 percent of any recovered funds to individuals who assist in freezing or recovering the stolen assets. The exchange is committed to a full investigation and transparency regarding the incident.

Synthesized by Vypr AI