Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.
Bitget did not disclose any details on how the attack took place, but said it has enlisted the help of Google-owned Mandiant and SlowMist for a third-party investigation.
The specific method of system intrusion remains under active investigation." The development comes about a week after SentinelOne attributed the North Korea-linked TraderTraitor group to an attack targeting an India-based information technology (IT) services company.
(The story was updated after publication to include more insights from Elliptic and TRM Labs.)
According to Bitget CEO Gracy Chen , assets impacted by the hack include ETH, XRP, BNB, AVAX, USDT, and USDC, with the chains involving Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base.
TraderTraitor is best known for the theft of $1.5 billion from Bybit and $292 million from KelpDAO's LayerZero bridge.
UTC, adding the vulnerability involved in the incident has been identified and addressed.
However, withdrawals have been temporarily suspended out of an abundance of caution while a "comprehensive security review" is underway.
If the Bitget theft turns out to be the work of North Korea, 2026 would become the second-largest year on record for North Korean crypto theft, reaching $1.04 billion, behind 2025's $1.68 billion.
TRM Labs has also uncovered multiple overlaps with wallets used to launder previous North Korean hacks, including Bybit and AFX Bridge, stating the overlaps point to the involvement of TraderTraitor.
What happened
Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.
Bitget did not disclose any details on how the attack took place, but said it has enlisted the help of Google-owned Mandiant and SlowMist for a third-party investigation.
What changed
The specific method of system intrusion remains under active investigation." The development comes about a week after SentinelOne attributed the North Korea-linked TraderTraitor group to an attack targeting an India-based information technology (IT) services company.
(The story was updated after publication to include more insights from Elliptic and TRM Labs.)
Why it matters
According to Bitget CEO Gracy Chen , assets impacted by the hack include ETH, XRP, BNB, AVAX, USDT, and USDC, with the chains involving Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base.
TraderTraitor is best known for the theft of $1.5 billion from Bybit and $292 million from KelpDAO's LayerZero bridge.
Technical details
UTC, adding the vulnerability involved in the incident has been identified and addressed.
Response
However, withdrawals have been temporarily suspended out of an abundance of caution while a "comprehensive security review" is underway.
Attribution
The Hacker News: Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.
What to watch next
Watch for new exploitation reports and updated indicators of compromise.
Watch for updated vendor guidance and fixed-version details.