DKDKCISSPSearch
Cyber Attacks

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.

DKCISSP News DeskThe Hacker News26 Sept 2026, 1:39 pm
Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.

Bitget did not disclose any details on how the attack took place, but said it has enlisted the help of Google-owned Mandiant and SlowMist for a third-party investigation.

The specific method of system intrusion remains under active investigation." The development comes about a week after SentinelOne attributed the North Korea-linked TraderTraitor group to an attack targeting an India-based information technology (IT) services company.

(The story was updated after publication to include more insights from Elliptic and TRM Labs.)

According to Bitget CEO Gracy Chen , assets impacted by the hack include ETH, XRP, BNB, AVAX, USDT, and USDC, with the chains involving Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base.

TraderTraitor is best known for the theft of $1.5 billion from Bybit and $292 million from KelpDAO's LayerZero bridge.

UTC, adding the vulnerability involved in the incident has been identified and addressed.

However, withdrawals have been temporarily suspended out of an abundance of caution while a "comprehensive security review" is underway.

If the Bitget theft turns out to be the work of North Korea, 2026 would become the second-largest year on record for North Korean crypto theft, reaching $1.04 billion, behind 2025's $1.68 billion.

TRM Labs has also uncovered multiple overlaps with wallets used to launder previous North Korean hacks, including Bybit and AFX Bridge, stating the overlaps point to the involvement of TraderTraitor.

What happened

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.

Bitget did not disclose any details on how the attack took place, but said it has enlisted the help of Google-owned Mandiant and SlowMist for a third-party investigation.

What changed

The specific method of system intrusion remains under active investigation." The development comes about a week after SentinelOne attributed the North Korea-linked TraderTraitor group to an attack targeting an India-based information technology (IT) services company.

(The story was updated after publication to include more insights from Elliptic and TRM Labs.)

Why it matters

According to Bitget CEO Gracy Chen , assets impacted by the hack include ETH, XRP, BNB, AVAX, USDT, and USDC, with the chains involving Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base.

TraderTraitor is best known for the theft of $1.5 billion from Bybit and $292 million from KelpDAO's LayerZero bridge.

Technical details

UTC, adding the vulnerability involved in the incident has been identified and addressed.

Response

However, withdrawals have been temporarily suspended out of an abundance of caution while a "comprehensive security review" is underway.

Attribution

The Hacker News: Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.

MORE IN CYBER ATTACKS

More cybersecurity reporting

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix LuresThe Hacker News · 30 Sept 2026, 9:22 pmRatHat's Evolving C2 Panel Points to Malware-as-a-Service Model - Infosecurity MagazineInfosecurity Magazine · 29 Sept 2026, 8:00 pmMicrosoft Warns NeedyMantis Malware Enables Persistent Network AccessInfosecurity Magazine · 29 Sept 2026, 7:00 pmMicrosoft Warns NeedyMantis Malware Enables Persistent Network AccessInfosecurity Magazine · 29 Sept 2026, 7:00 pm