Today·Emerging
Follow-up 1h ago Major10
96%
Bitget Confirms $351.6M Crypto Theft, Suspects North Korean Hackers
Cryptocurrency exchange Bitget confirmed a $351.6 million breach on September 24, 2026, in which attackers compromised its wallet backend system and spoofed transaction data to drain funds from hot and warm wallets without stealing private keys. CEO Gracy Chen attributed the attack to patterns consistent with North Korean hacker organizations based on IP and on-chain analysis, though no technical evidence has been released. Bitget suspended withdrawals pending security review but stated the loss is fully covered by its $464 million User Protection Fund, with customer balances unaffected.
Quick Facts
- Unauthorized transfers from hot and warm wallets
- Backend system compromise and transaction data spoofing
- Withdrawal suspension implemented
- Customer account balances verified as accurate
- Cold wallets confirmed secure





Cryptocurrency exchange Bitget announced on September 24, 2026, that unauthorized transfers totaling $351.6 million had been removed from its hot and warm wallet layers following a backend system compromise. The breach was detected at 18:31 UTC when Bitget's security systems flagged the unauthorized activity. The attackers exploited a compromised backend system to spoof transaction data and trigger the exchange's authorization process, enabling fund transfers without stealing private keys. Bitget immediately suspended withdrawals as a precautionary measure while maintaining normal deposit and trading operations.
Bitget confirmed that cold wallets—its offline storage vault—remained fully secure and unaffected by the attack. The exchange stated that customer account balances are accurate and that further unauthorized transfers have been prevented. CEO Gracy Chen disclosed that the stolen assets included ETH, XRP, BNB, AVAX, USDT, USDC and other tokens across multiple blockchain networks including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. Bitget has contacted the foundations of affected blockchain networks, with some confirming the freezing of attacker-controlled wallet addresses.
Gracy Chen attributed the attack to patterns consistent with North Korean hacker organizations based on IP behavior analysis and on-chain analysis. No technical evidence supporting this attribution has been publicly released. The company has engaged third-party investigators including Google-owned Mandiant and SlowMist to assist in the investigation. Chen clarified that Bitget Wallet, the exchange's decentralized wallet product, operates on completely separate infrastructure and was not affected by the incident.
Bitget stated that its User Protection Fund, which holds more than $464 million, fully covers the $351.6 million loss. The exchange pledged to publish a complete incident report within 24 hours, including root cause analysis and corrective measures. Multiple technical teams are working on system remediation and security hardening, though no specific timeline for withdrawal resumption has been provided. The theft marks one of 2026's largest cryptocurrency thefts, pushing September's total reported crypto losses to approximately $684 million, making it the costliest month for crypto security losses in 2026 to date.
Why This Matters
Bitget's $351.6 million theft affects cryptocurrency liquidity, market confidence in exchange security infrastructure, and operational continuity for platforms offering withdrawal services. The breach method—backend compromise enabling transaction spoofing without private key theft—signals a new attack vector for custodial systems. Blockchain networks are implementing address freezes; investigation timelines and asset recovery remain unspecified. This incident contributed to September 2026 recording $684 million in reported crypto losses, the highest monthly total for 2026.
Timeline & Sources
Sep 24, 2026
WireCEO Gracy Chen posted incident notice on X (early September 25 Singapore time)
Sep 24, 2026
WireBitget security systems detect unauthorized transfers from hot wallets; emergency response procedures activated
Sep 25, 2026
WireCEO Chen provides detailed attack explanation: backend compromise and transaction spoofing
Sep 25, 2026
WireFull incident report due (24 hours from initial disclosure)
Related Signals
Sources
- Bitget Says $351 Million Affected in Breach, Halts WithdrawalsBloomberg.comWireSep 24, 2026
- North Korean hackers suspected in $351M crypto theft, the largest so far this yeartechcrunchMediaSep 25, 2026
- More than $170 million in crypto moves from Bitget wallets to unidentified addressThe BlockMediaSep 25, 2026
- Bitget’s $351.6 million hack pushes September crypto losses to 2026 highCryptoRankMediaSep 25, 2026
- Bitget loses $351.6 million to hackers, so why is BGB barely flinching? Follow up.investingLiveMediaSep 25, 2026
- Bitget Confirms $351.6 Million Hack, Suspects North Korea’s Lazarus GroupHackreadMediaSep 25, 2026
- 加密货币交易所Bitget被盗4.5亿元zaobaoMediaSep 25, 2026
- Hackers steal $351.6m from Bitget walletsPunch NewspapersMediaSep 25, 2026
- Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gray Chen saysCoinDeskMediaSep 25, 2026
- Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromisethe_hacker_newsMediaSep 25, 2026