Ethical Hacking News
North Korea's Cryptocurrency Heist: A Look into the $388 Million Hack of Bitget
The cryptocurrency exchange Bitget has been hit with a $388 million heist, believed to be the largest single suspected North Korean crypto theft of 2026. The breach was detected on September 24, 2026, and investigators have ruled out a private-key compromise. The attack is believed to be linked to the Lazarus group, a state-backed hacking crew responsible for previous North Korean cyber attacks. The breach highlights the need for greater security measures in the cryptocurrency industry. Bitget has launched a recovery bounty and a withdrawal plan to recover some of the stolen funds.
The cryptocurrency exchange Bitget has been hit with a $388 million heist, which is believed to be the largest single suspected North Korean crypto theft of 2026. According to an official incident notice and a post from CEO Gracy Chen, the breach reached parts of Bitget's hot and warm wallet layers, but cold wallets, which sit offline, were not affected. The breach was detected on September 24, 2026, at 18:31 UTC, and investigators have ruled out a private-key compromise.
The attacker compromised a critical backend system within Bitget's wallet infrastructure, used it to spoof transaction data, and triggered the authorization process to move funds out, as stated by Chen. The incident notice stated that the breach was contained, and the exchange's user protection fund covers the loss. However, withdrawals are still frozen pending a security review.
The hack has raised concerns about North Korea's alleged involvement, with Chen linking the incident to North Korea during a live Q&A on X. Chen mentioned that they have identified some IP addresses that match the VPN choices by a certain DPRK group, which resembles the pattern of previous North Korean cyber attacks. Blockchain analytics firm Elliptic has also assessed the Bitget attack as "highly likely" to be linked to North Korea.
The breach has been linked to the Lazarus group, a state-backed hacking crew that operates under the North Korean military intelligence services. The group is also responsible for the $1.4 billion Bybit heist, which was previously linked to the same IP addresses as the Bitget hack. MetaMask's Taylor Monahan had already written that the Bitget loot landed in an address that previously received Bybit stolen funds, and she named Lazarus as the actor.
The Bitget hack is part of a larger trend of North Korean cyber attacks, which have resulted in losses of over $6 billion since 2017. In April, TRM Labs put the regime's total take since 2017 above $6 billion, and said North Korean agents accounted for 76% of stolen crypto value through that month. The Bitget hack is the largest single suspected North Korean crypto theft of 2026, pushing those heists past $1 billion this year.
The crypto industry has been watching frontier AI models get better at finding critical bugs before they could be patched. OpenZeppelin co-founder Manuel Aráoz previously went as far as telling friends and family to exit DeFi, including names usually treated as blue chips, because "coding agents are superhuman at finding vulnerabilities."
Earlier this month, a bug in Blockstream's Liquid Network software let attackers mint unbacked L-BTC and cash out roughly 4,000 bitcoin, then worth about $320 million, without stealing the federation's keys. That episode followed a previous Coldcard hardware wallet vulnerability that had already been exploited for more than $100 million in bitcoin.
The Bitget hack has also highlighted the need for greater security measures in the cryptocurrency industry. Circle and Tether separately blacklisted one related address holding about $318,000 in USDC and USDT, a sliver next to the ether the thieves moved that no issuer can freeze. The incident notice stated that the breach was contained, and the exchange's user protection fund covers the loss. However, withdrawals are still frozen pending a security review.
In response to the hack, Bitget has launched a recovery bounty, offering 5% for voluntarily freezing attacker funds and 5% for voluntary recovery, plus a tracing dashboard and a path to submit leads through Bybit's Lazarusbounty site. The exchange has also announced a withdrawal plan by September 26 at 4:00 AM UTC.
Related Information:
https://www.ethicalhackingnews.com/articles/North-Koreas-Cryptocurrency-Heist-A-Look-into-the-388-Million-Hack-of-Bitget-ehn.shtml
https://gizmodo.com/north-korea-very-likely-behind-388-million-hack-of-crypto-exchange-bitget-2000817421
Published: Fri Sep 25 11:59:05 2026 by llama3.2 3B Q4_K_M