Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Cryptocurrency Exchange Bitget Falls Victim to Sophisticated North Korea-Linked Hack, $351.6 Million Stolen




Cryptocurrency exchange Bitget has fallen victim to a sophisticated North Korea-linked hack, resulting in the theft of $351.6 million from hot and warm wallets. The attack highlights the vulnerability of cryptocurrency exchanges to sophisticated cyber attacks and the need for robust security measures to protect user assets. The incident serves as a reminder of the importance of staying vigilant against North Korean hackers and implementing robust security measures to protect user assets.



  • Bitget, a cryptocurrency exchange serving over 120 million users, fell victim to a sophisticated North Korea-linked hack.
  • $351.6 million was stolen from hot and warm wallets, with the attackers compromising a critical backend system and spoofing transaction data.
  • The attack is consistent with known patterns of North Korean hacker organizations, and some foundations have frozen hacker wallet addresses.
  • The incident highlights the vulnerability of cryptocurrency exchanges to sophisticated cyber attacks and the need for robust security measures.
  • The theft affected multiple blockchains, including ETH, XRP, BNB, AVAX, USDT, and USDC.
  • The incident is part of a growing concern about North Korea's involvement in cybercrime, with estimated losses of $6.75 billion in cryptocurrency stolen by DPRK-linked actors in 2025.



  • Cryptocurrency exchange Bitget, a Universal Exchange that serves over 120 million users in more than 150 countries and regions, has fallen victim to a sophisticated North Korea-linked hack. The incident, which occurred on September 24, 2026, resulted in the theft of $351.6 million from hot and warm wallets, according to reports from the exchange. The attackers compromised a critical backend system within Bitget's wallet infrastructure, used it to spoof transaction data, and triggered the authorization process to move funds.

    The attack method employed by the attackers is highly consistent with known patterns of North Korean hacker organizations, according to Gracy Chen, CEO of Bitget. The exchange has contacted the foundations of all affected chains and has confirmed that some foundations have frozen hacker wallet addresses. The company's security team immediately activated emergency response procedures and began a full investigation upon detecting unauthorized transfers involving a limited number of hot wallets at 18:31 UTC on September 24, 2026.

    The theft affected ETH, XRP, BNB, AVAX, USDT, and USDC across several blockchains. The attackers reportedly bypassed the authorization process to move funds, compromising a critical backend wallet system and spoofing transaction data. The incident highlights the vulnerability of cryptocurrency exchanges to sophisticated cyber attacks and the need for robust security measures to protect user assets.

    The incident is not surprising, given the history of North Korean hackers targeting cryptocurrency exchanges and other digital-asset services. Chainalysis reported that North Korean hackers stole at least $2.02 billion in cryptocurrency in 2025, bringing the estimated total stolen by DPRK-linked actors to $6.75 billion. The thefts increasingly target crypto exchanges and other digital-asset services, with attackers using techniques ranging from sophisticated cyber intrusions to fake IT-worker identities.

    The impact of the incident is significant, with $351.6 million stolen from Bitget's users. The exchange has assured users that customer balances, cold wallets, and most platform assets remain secure, and that the User Protection Fund covers the impact on the platform-wide incident. The company has also confirmed that Bitget Wallet operates as a self-custodial wallet on a completely separate and independent infrastructure from Bitget Exchange and was not affected by this incident. The assets on Bitget Wallet remain onchain under users' control and remain unaffected.

    In response to the incident, Bitget is working with independent third-party experts Mandiant and SlowMist for a full investigation. The exchange has also contacted the foundations of all affected chains and has confirmed that some foundations have frozen hacker wallet addresses. The incident serves as a reminder of the importance of robust security measures and the need for cryptocurrency exchanges to stay vigilant against sophisticated cyber attacks.

    The incident also highlights the growing concern about North Korea's involvement in cybercrime. The use of North Korean-linked threat actors in the attack on Bitget is consistent with known patterns of North Korean hacker organizations. The incident serves as a warning to cryptocurrency exchanges and other digital-asset services to remain vigilant against North Korean hackers and to implement robust security measures to protect user assets.

    In conclusion, the attack on Bitget highlights the vulnerability of cryptocurrency exchanges to sophisticated cyber attacks. The incident serves as a reminder of the importance of robust security measures and the need for cryptocurrency exchanges to stay vigilant against North Korean hackers. The exchange's response to the incident and its commitment to user protection demonstrate its dedication to its users and its resolve to protect their assets.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Cryptocurrency-Exchange-Bitget-Falls-Victim-to-Sophisticated-North-Korea-Linked-Hack-3516-Million-Stolen-ehn.shtml

  • https://securityaffairs.com/199754/cyber-crime/cryptocurrency-exchange-bitget-says-north-korea-linked-hackers-stole-351-6-million.html


  • Published: Fri Sep 25 14:16:35 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us