Skip to main content
Emerging ThreatsMalware & Ransomware

North Korean Hackers Steal $351.6M from Bitget in Backend Compromise

Cryptocurrency exchange trading floor with screens and terminals, hint of security monitoring area.

"At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," BitGet said in a post shared on X.

BitGet confirms $351.6 million taken from hot and warm wallets

Cryptocurrency exchange BitGet reported that suspected North Korean threat actors stole $351.6 million from its hot and warm wallets. The company said deposits and trading continued to operate normally and that customer account balances remained accurate, but that withdrawals were temporarily suspended while a "comprehensive security review" is underway.

BitGet emphasized that its cold wallets and "the overwhelming majority of platform assets remain secure and unaffected." The company also noted that Bitget Wallet — described as a self-custodial wallet running on separate and independent infrastructure from BitGet Exchange — was not affected.

Assets and chains identified by the company

BitGet CEO Gracy Chen provided a list of impacted assets: ETH, XRP, BNB, AVAX, USDT, and USDC. Chains named in the company’s statements included Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. Chen said BitGet had contacted the foundations of all affected chains and that some foundations had confirmed freezing hacker wallet addresses.

Company description of intrusion and attribution language

BitGet said the attacker "compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation."

Based on IP behavior patterns and on-chain analysis, BitGet said the attack "is highly consistent with known patterns of North Korean hacker organizations." The company did not disclose further technical details about how the incident occurred.

Third-party response: Mandiant, SlowMist, and on-chain freezes

BitGet said it had enlisted Google-owned Mandiant and SlowMist to conduct third-party investigations. The company also reported contacting affected chain foundations; Chen said "some foundations have confirmed the freezing of hacker wallet addresses."

The company has stopped withdrawals as a precaution while the investigation proceeds and while teams attempt to trace and, where possible, freeze or recover stolen funds through coordination with chain foundations and third-party responders.

What this means for customers, exchanges, and chain foundations

  • Customers and end users: BitGet has stated account balances are accurate and that trading and deposits continue. Users will be directly affected by the withdrawal suspension and will watch the company’s security review for timing on restoring normal withdrawal operations.
  • Exchange and security teams: The company’s description centers on a compromised backend system and spoofed transaction data. Exchange security teams will focus on internal backend controls, authorization logic, and systems that tie wallet infrastructure to transaction authorization.
  • Chain foundations and custodial freeze agents: BitGet said it contacted the foundations of affected chains and that some had confirmed freezing attacker addresses. Those foundations — and any custodial or governance mechanisms they operate — play a direct role in either halting onward movement of assets or enabling recovery steps where protocol governance allows.

This incident arrives about a week after SentinelOne attributed an attack on an India-based IT services company to the North Korea-linked TraderTraitor group, which the report noted is known for large-scale thefts from crypto platforms. BitGet’s public statements stop short of naming a specific group beyond saying the activity is "highly consistent with known patterns of North Korean hacker organizations."

BitGet’s immediate priorities, as stated, are to complete the third-party investigation with Mandiant and SlowMist, coordinate with affected chain foundations on address freezes, and finish a comprehensive security review that will determine when withdrawals can safely resume. The company’s claim that "no further unauthorized transfers are possible" frames the next phase of the response as containment and recovery rather than ongoing theft.

For now, the core facts are narrow and concrete: $351.6 million taken from hot and warm wallets; cold wallets and the self-custodial Bitget Wallet described as unaffected; outside investigators engaged; and some on-chain freezes confirmed by chain foundations. The specific method of intrusion, and whether further legal or technical remedies will recover funds, remain to be demonstrated as investigators complete their work.

Original story