HomeSecurityBitget: Is North Korea behind the theft of $351.6 million?

Bitget: Is North Korea behind the theft of $351.6 million?

One of the largest crypto attacks of 2026 is under investigation after an estimated $351.6 million worth of digital assets was stolen from Bitget. The company says the attackers’ method of operation bears significant similarities to techniques previously used by hacking groups linked to North Korea.

Article Image: North Korea Suspected in $351 Million Bitget Crypto Heist

This assessment, however, does not yet constitute a definitive attribution of the attack to a specific group. The investigation is ongoing, with the participation of Mandiant and SlowMist, among others, and the relevant authorities have also been informed.

Hot wallets in the spotlight

Bitget announced that its security systems detected unauthorized transfers on September 24, immediately activating incident response procedures. The company clarified that the breach was limited to a portion of the hot wallet, while cold wallets remained secure.

This distinction is particularly important for exchange security. Hot wallets are connected to systems that allow for fast transactions and withdrawals, making them convenient but also more vulnerable to cyberattacks. In contrast, cold wallets keep funds offline and are typically used to store the bulk of their reserves.

See also: Bitget: Cold wallets secure after 351.6 million breach

Bitget also stated that Bitget Wallet, its self-custodial wallet, operates on separate infrastructure and was not affected by the incident.

Private keys were not compromised

Of particular interest is the manner in which the theft appears to have been carried out. According to findings so far, the attacker allegedly gained access to a critical backend system of the wallet infrastructure and used it to create or manipulate transaction data, ultimately leading to the approval of unauthorized transfers.

Bitget claims that private keys were not compromised. This element shifts the focus from classic key theft to a different attack model: the breach of the systems that manage and approve transactions. SlowMist lists as a preliminary finding the breach of an internal system and the exploitation of the exchange's authorization process.

ETH, XRP and stablecoins in stolen funds

The stolen assets were spread across multiple blockchains and included ETH, XRP, BNB, AVAX, USDT, and USDC. XRP was the largest individual loss, with more than 102 million XRP moved, worth approximately $157 million.

After the theft, investigators began tracking the movements of funds via blockchain. Some of the assets were moved between different networks and swaps were performed, a practice that can make it difficult to immediately trace and recover the funds.

See also: The North Face: Credential stuffing attacks allowed data breach

Bitget said that addresses linked to the suspicious transactions have been identified and reported, and in some cases, mitigation mechanisms have been activated by ecosystem players. Recovery, however, remains a complex process, as the nature of blockchains allows stolen assets to move quickly between wallets and networks.

Bitget: Is North Korea behind the theft of $351.6 million?

Why is the North Korea scenario being considered?

Bitget CEO Gracy Chensaid that analysis of IP addresses and on-chain data showed significant similarities to known patterns of activity by North Korean hacking groups. She did not name a specific group or release detailed technical data that would allow independent verification of the performance.

The case takes on particular significance given North Korea’s history with cryptocurrency. The FBI had previously attributed the theft of approximately $1.5 billion from Bybit to North Korea in February 2025, an incident that once again highlighted the role of digital assets as a target for organized state-sponsored operations.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Another reminder about crypto security

The Bitget attack highlights a critical issue for exchanges: protecting private keys alone is not enough. Even when keys remain secure, a successful intrusion into backend mechanisms, approval processes, or wallet management systems can lead to huge financial losses.

See also: CISA: Warns of vulnerabilities in CyberPanel, North Grid, ProjectSend and Zyxel Firewalls

Bitget has temporarily suspended withdrawals, while claiming that user funds are covered by its User Protection Fund, which has more than $464 million. The company has pledged to publish a full report on the cause of the breach and corrective measures.

The next critical step is to determine exactly how the initial access to the backend. Until the investigation is complete, the connection to a North Korean group should be treated as an estimate and not a definitively confirmed identification. At the same time, the case shows how important multi-layered defense has become in crypto platforms, where a single compromised internal system can become a gateway for thefts of hundreds of millions of dollars.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS