Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
Headline by Prism · from 1 report
Cryptocurrency exchange Bitget reported a $351.6 million theft from its hot and warm wallets, which it attributes to suspected North Korean hackers.
The Hacker NewsThe brief
Written by software from the 1 report below.
- Bitget identified unauthorized transfers from its hot and warm wallets on September 24, 2026.
- The exchange suspended withdrawals to conduct a comprehensive security review following the incident.
- Investigations by the company and third-party firms indicate the attack method matches patterns of North Korean threat groups.
- The firm confirmed that its cold wallets and Bitget Wallet infrastructure remain secure and unaffected.
What to watch next
- Progress of the Recovery Bounty Program to freeze and return stolen assets.
- Results of the ongoing comprehensive security review into the backend system compromise.
- Potential recovery or freezing of funds by blockchain foundations.
The points restate the reports; where one says why it matters, that is Prism's reading, not a reported fact.
Who said what
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Gracy Chen
CEO
2 quotes · 1 outlet
“Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations.”
In the article
…Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. "We have contacted the foundations of all affected chains, and some foundations have confirmed the freezing of hacker wallet addresses," Chen said. " Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations. " "The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out. No further unauthorized transfers are…
“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out.”
In the article
…freezing of hacker wallet addresses," Chen said. "Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations." " The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation." The development comes about a week after SentinelOne attributed the North Korea-linked…
Coverage
1 outlet
All filed from India
NamedNorth Korea · Bitget · Ari Redbord · Elliptic · Gracy Chen · Mandiant · SlowMist · TraderTraitor · TRM Labs
The 1 report is listed beside the record.
Corrections and versions
A correction says what was wrong and why. Every earlier headline and brief of this record is kept.
Something wrong?
Say what, and it arrives with this record's address filled in. A correction is welcome.
Ask this story
Answers cite the 1 report above, or say they can't.