Technology 15 sources · over 3 days Latest coverage 27 Sept 2026, 6:33 pm UTC

Bitget Crypto Exchange Hacked, $387.5 Million Stolen in Suspected North Korean Attack

Bitget, a major crypto exchange, suffered one of the largest crypto thefts of the year, with losses rising to $387.5 million and North Korean hackers suspected of orchestrating the attack.

By Hannah Lindqvist · First published 27 Sept 2026

In brief

  1. Bitget was hacked on September 24, with attackers stealing $351.6 million from its hot and warm wallets.
  2. The company later revised the stolen amount to $387.5 million after a broader asset review.
  3. North Korean hackers are strongly suspected of carrying out the attack by spoofing transaction requests.
  4. Bitget has paused all customer withdrawals and claims it will use a protection fund to cover the losses.
  5. Investigations are ongoing while some stolen funds are reportedly moving through various wallets.
Bitget Crypto Exchange Hacked, $387.5 Million Stolen in Suspected North Korean Attack
Source: The Register

Timeline · 6 moments

6 moments Open the full timeline →

Bitget detects unauthorized crypto transfers from hot wallets

Wu Blockchain ↗

Bitget confirms $351.6 million stolen, pauses withdrawals

BleepingComputer ↗

Company suspects North Korean hackers in the attack

Financial Times ↗

Bitget says attack involved spoofed transaction requests

DEV Community ↗

Exchange reassures users its protection fund will cover losses

Gizmodo Tech ↗

Stolen XRP tracked moving through multiple wallets

Breaking News on Seeking Alpha Business & Economy ↗

How it started

Bitget, a prominent cryptocurrency exchange, detected suspicious activity in its systems on September 24. Its security team noticed unauthorized transfers from some of the company's hot wallets, which are online wallets used for active trading and withdrawals.

The initial loss estimates were over $350 million. The attack was sophisticated, involving the spoofing of transaction requests that tricked the exchange's own approval systems into moving funds to the attackers.

How it unfolded

On September 24, Bitget's security system flagged abnormal fund outflows at 18:31 UTC. The company quickly confirmed a large-scale breach and began investigating the scope of the theft.

By September 25, Bitget officially disclosed that $351.6 million had been stolen. The company paused all customer withdrawals to prevent further losses and stated that North Korean hackers were the prime suspects, based on the techniques used.

Further analysis revealed that the attackers had compromised a critical backend system, allowing them to spoof transaction data and bypass internal controls. As investigations continued, Bitget revised the estimated losses upward to $387.5 million after including assets such as Zcash and TRON that were previously omitted.

During this period, Bitget reassured customers that its bitcoin-backed protection fund would cover the losses, and emphasized that private keys had not been stolen. Meanwhile, some wallet addresses linked to the attackers were frozen, but stolen assets, including XRP, were seen moving through other wallets.

Where it stands

Bitget has suspended all withdrawals while investigations and asset tracing continue. The company maintains it will cover customer losses using its protection fund.

North Korean hackers remain the leading suspects, and the incident has pushed North Korea's alleged crypto thefts past $1 billion for the year. Some of the stolen funds are still in motion, making asset recovery efforts ongoing.

What to watch

Customers are waiting to see when withdrawals will resume and whether Bitget's protection fund will fully cover the stolen assets. Investigators are also tracking the movement of stolen cryptocurrencies in hopes of recovering some of the funds. The outcome may influence security standards across the crypto exchange sector.

Written from 15 outlets' coverage of this story. Every timeline entry links to the original report.

More in Technology

All →