Ethical Hacking News
North Korea-linked hackers have stolen $351.6 million from cryptocurrency exchange Bitget, highlighting the vulnerability of cryptocurrency exchanges to state-sponsored cyber threats. The attack raises concerns about the effectiveness of current security measures and the need for increased vigilance, cooperation, and regulatory oversight.
Bitget, a popular cryptocurrency exchange, was hacked, resulting in the theft of $351.6 million from its hot and warm wallets. The attack is believed to have been perpetrated by suspected North Korean hackers. Bitget has temporarily suspended withdrawals and initiated a comprehensive security review after identifying unauthorized transfers. The attackers exploited a critical backend system within Bitget's wallet infrastructure, allowing them to spoof transaction data and trigger the authorization process. The stolen assets include ETH, XRP, BNB, AVAX, USDT, and USDC from various blockchain chains. The attack highlights the vulnerability of cryptocurrency exchanges to state-sponsored cyber threats and the need for increased vigilance, cooperation, and regulatory oversight.
Bitget, a popular cryptocurrency exchange, has recently fallen victim to a significant cyber attack, resulting in the theft of $351.6 million from its hot and warm wallets. The attack, which is believed to have been perpetrated by suspected North Korean hackers, has raised concerns about the vulnerability of cryptocurrency exchanges to state-sponsored cyber threats.
According to a statement released by Bitget, the security systems identified unauthorized transfers involving a limited number of hot wallets at 18:31 UTC on September 24, 2026. The company emphasized that customer account balances remain accurate, and deposits and trading continue to operate normally, but withdrawals have been temporarily suspended out of an abundance of caution while a "comprehensive security review" is underway.
The attack is believed to have occurred when a critical backend system within Bitget's wallet infrastructure was compromised, allowing the attackers to spoof transaction data and trigger the authorization process to move funds out. The specific method of system intrusion remains under active investigation, but Bitget has enlisted the help of Google-owned Mandiant and SlowMist for a third-party investigation.
The stolen assets include ETH, XRP, BNB, AVAX, USDT, and USDC, with the chains involving Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. Bitget has contacted the foundations of all affected chains, and some foundations have confirmed the freezing of hacker wallet addresses.
According to Bitget CEO Gracy Chen, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations. The development comes about a week after SentinelOne attributed the North Korea-linked TraderTraitor group to an attack targeting an India-based information technology (IT) services company.
The theft of $351.6 million from Bitget is significant, not only because of the large amount of money involved but also because it highlights the vulnerability of cryptocurrency exchanges to state-sponsored cyber threats. The attack raises concerns about the effectiveness of current security measures and the need for increased vigilance and cooperation between cryptocurrency exchanges, law enforcement agencies, and cybersecurity experts.
Furthermore, the attack highlights the importance of threat intelligence and incident response in the cryptocurrency space. Bitget's decision to temporarily suspend withdrawals and initiate a comprehensive security review demonstrates a commitment to protecting customer assets and maintaining the integrity of the platform.
However, the attack also raises questions about the effectiveness of current regulatory frameworks and the need for increased oversight and enforcement. The fact that the attackers were able to exploit a critical backend system within Bitget's wallet infrastructure suggests that there may be vulnerabilities in the platform's security architecture that need to be addressed.
In conclusion, the theft of $351.6 million from Bitget is a significant cyber attack that highlights the vulnerability of cryptocurrency exchanges to state-sponsored cyber threats. The attack raises concerns about the effectiveness of current security measures and the need for increased vigilance, cooperation, and regulatory oversight.
Related Information:
https://www.ethicalhackingnews.com/articles/North-Korea-Linked-Hackers-Stole-3516-Million-from-Cryptocurrency-Exchange-Bitget-ehn.shtml
https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html
https://www.cnbc.com/2026/09/25/crypto-platform-bitget-suspects-north-korea-in-352-million-hack.html
Published: Fri Sep 25 06:17:38 2026 by llama3.2 3B Q4_K_M