Bitget Suspects North Korean Hackers Behind $352 Million Crypto Theft
Bitget believes North Korean hackers may be responsible for a $351.6 million breach targeting its hot and warm wallet systems, as the platform's BGB token dropped roughly 3%. Photo: X / bitget
Crypto

Bitget Suspects North Korean Hackers Behind $352 Million Crypto Theft

Bitget suspects North Korean hackers may be behind a $351.6 million security breach that compromised parts of the crypto exchange’s hot and warm wallet infrastructure.

By David Sinclair • 4 mins read Edited by Oleg Petrenko Published:

Crypto exchange Bitget is investigating a $351.6 million security breach after attackers transferred hundreds of millions of dollars in digital assets from portions of its hot and warm wallet infrastructure, making it one of the largest cryptocurrency exchange hacks of 2026.

Bitget CEO Gracy Chen said preliminary evidence suggests hackers linked to North Korea may have been responsible. Investigators identified IP addresses associated with VPN services previously used by a DPRK-linked group, while aspects of the attack resembled earlier North Korean operations. The attribution remains preliminary, and Bitget has not publicly established which hacking organization carried out the attack.

Bitget Loses More Than $350 Million

Bitget detected unauthorized transfers at 18:31 UTC on September 24 and activated its emergency response procedures within minutes. The exchange subsequently estimated the total value of affected assets at approximately $351.6 million.

The largest identified loss was approximately 102.93 million XRP worth $157.5 million, according to onchain data cited by CCN. Attackers also obtained around 31,890 ETH worth $85.8 million, $34.75 million in USDT, $21.05 million in USDC and additional assets including BNB, AVAX, TRX and tokenized gold.

Bitget says its private keys were not compromised. Preliminary findings instead point toward a breach of backend wallet infrastructure that allowed attackers to transfer funds without using the normal customer withdrawal process. Investigators are still working to establish the precise entry point.

The company temporarily suspended withdrawals while deposits and trading remained operational. Bitget has not yet provided a confirmed timetable for fully restoring withdrawals.

BGB Falls Following the Hack

Bitget is privately held and therefore has no publicly traded stock or exchange ticker whose reaction can be measured. The closest market indicator is Bitget Token, or BGB, the native token associated with the platform.

BGB traded around $1.97 on September 25, down approximately 3.3% over 24 hours, with a market capitalization of roughly $1.38 billion. The token traded between $1.89 and $2.07 during the period as investors reacted to the security breach.

The relatively limited decline is notable given the scale of the theft, although withdrawals from Bitget remain suspended, complicating interpretation of the immediate market reaction.

Several publicly traded companies also have exposure to assets involved in the incident. Circle Internet Group, Inc. (NYSE: CRCL) issues USDC, approximately $21 million of which was identified among the stolen assets. Tether, which issues USDT and Tether Gold, remains privately held.

There is currently no indication that Circle’s infrastructure itself was compromised. The affected USDC was held within Bitget’s wallet infrastructure, making the incident a Bitget security breach rather than an attack on Circle.

North Korea Emerges as Leading Suspect

Chen said Bitget’s investigation uncovered IP addresses matching VPN infrastructure previously associated with a North Korean hacking group.

“The pattern looks very much like what the North Korean team did before,” Chen said during a live Q&A following the incident, while emphasizing that the investigation remains ongoing.

North Korean hackers have become a major threat to cryptocurrency platforms. The FBI attributed the approximately $1.5 billion Bybit hack in February 2025 to North Korea, demonstrating the scale and sophistication of state-linked operations targeting digital assets.

Onchain researchers have also identified possible links between funds stolen from Bitget and addresses associated with previous exploits. Those findings strengthen suspicions but do not yet constitute definitive attribution.

Bitget Says Customers Will Be Protected

Despite the size of the breach, Bitget says customer balances will not be affected. The exchange’s User Protection Fund currently holds more than $464 million, exceeding its initial estimate of the amount stolen.

Bitget also said its cold wallets remain secure and that the incident was contained to portions of its hot and warm wallet layers. Some addresses associated with the attackers have already been frozen with assistance from blockchain organizations, although the amount potentially recoverable remains unclear.

The incident nevertheless exposes another vulnerability facing centralized crypto exchanges. Even when private keys remain secure, attackers may target the backend systems responsible for constructing, authorizing and processing transactions.

For Bitget, the immediate challenge is restoring withdrawals and determining exactly how attackers penetrated its infrastructure. The longer-term consequences will depend on how much cryptocurrency can be recovered and whether investigators ultimately confirm the suspected North Korean connection.

With approximately $352 million affected, the attack represents another reminder that crypto platforms remain lucrative targets even as exchange custody and security systems become increasingly sophisticated.

Crypto, Markets, News

More from MarketSpeaker

Apple Tests Screenless Fitness Band to Challenge Whoop and Oura

Apple Tests Screenless Fitness Band to Challenge Whoop and Oura

by • 4 mins read

Apple is testing a screenless fitness band designed for continuous health monitoring as the iPhone maker explores a new wearable category dominated by Whoop, Oura and other fitness…