Crypto platform Bitget suspects North Korea is responsible for $352 million hack
PUBLISHED Sep 25, 2026, 4:50 AM ET
Read, Watch or Listen
Cryptocurrency exchange Bitget confirmed an unauthorized outflow of assets totaling approximately $351.6 million following a security breach affecting portions of its hot and warm wallet infrastructure. The incident was detected on September 24, 2026, at 18:31 UTC when security systems identified unauthorized transfers involving several digital assets. Bitget Chief Executive Officer Gracy Chen stated during a live broadcast on X that preliminary findings suggest North Korean state-backed hackers, specifically the Lazarus Group, were behind the attack. According to the exchange, investigators traced suspicious IP addresses and virtual private network usage patterns that matched previous cyberattacks attributed to North Korean threat actors. Chen reported that the hackers breached a critical backend system of the wallet infrastructure rather than forging user withdrawal requests. The attackers manipulated transfer details internally to trigger regular signing processes. Bitget confirmed that its cold wallets remained completely secure and offline, and user private keys were not compromised. Among the affected digital assets, XRP accounted for the largest stolen volume, valued at nearly $157.5 million. Other impacted cryptocurrencies included Ethereum, BNB, USDT, and USDC. Following the detection of the breach, Bitget temporarily suspended platform withdrawals while leaving trading and deposits available. The exchange flagged the recipient wallet addresses, contacted law enforcement agencies, and coordinated with blockchain security firms and token foundations to freeze illicit funds. Bitget announced that the total stolen amount is fully covered by its User Protection Fund, which held more than $464 million at the time of the incident. The exchange stated that customer balances remain accurate and secure, while security teams continue a comprehensive forensic investigation into how the attackers gained initial entry into the internal backend systems.
By Neha R. | JQJO News
Timeline of Events
- On September 24 2026 Security systems detect unauthorized transfers involving several digital assets from Bitget wallet infrastructure.
- On September 24 2026 Bitget temporarily suspends platform withdrawals following the security breach.
- On September 25 2026 Bitget CEO Gracy Chen announces during a live broadcast on X that North Korea's Lazarus Group is suspected.
- On September 25 2026 Bitget confirms full coverage of the $351.6 million loss via its User Protection Fund.
- On September 25 2026 Law enforcement agencies and blockchain security firms coordinate to freeze illicit funds and conduct forensic analysis.
News Intelligence
- Immediate US impact: U.S. cryptocurrency traders and institutional investors face heightened risk awareness regarding centralized exchange wallet security and potential token volatility.
- Possible long-term US impact: Intensified regulatory scrutiny on global cryptocurrency exchange compliance, asset protection reserves, and state-sponsored cyber threat mitigation.
- Most affected groups: Cryptocurrency holders, digital asset exchanges, and cybersecurity regulators.
- Reader priority: Understanding exchange solvency, asset protection fund coverage, and state-backed cyber threats in decentralized finance.
- Articles Published:
- 29
- Right Leaning:
- 3
- Left Leaning:
- 5
- Neutral:
- 21
- Distribution:
- Left 17%, Center 72%, Right 10%
Left: leaning outlets emphasize the regulatory risks, consumer protection concerns, and the systemic vulnerabilities of lightly regulated cryptocurrency platforms facing state-sponsored cyber operations. Center: outlets focus objectively on the technical facts of the breach, blockchain forensics, attribution evidence linking the attack to North Korea's Lazarus Group, and Bitget's reserve fund coverage. Right: leaning outlets highlight national security implications involving foreign state adversaries like North Korea, the need for enhanced defensive cybersecurity infrastructure, and free-market resilience.
Initial reporting on Bitget $352 million hack and Lazarus Group attribution. https://hackread.com/bitget-hack-suspects-north-koreas-lazarus-group/
Coverage of Story:
From Left
CNN Business News
CNN Business Los Angeles Times New York Times Washington Post The GuardianFrom Center
CoinDesk - Bitcoin, Ethereum, Crypto News and Price Data
CoinDesk Cointelegraph The Block Decrypt TechCrunch Wired Ars Technica The Verge Reuters Bloomberg CNBC Financial Times Forbes Associated Press USA Today BBC News ZDNet Dark Reading Bleeping Computer The Hacker News Bank Info Security
Comments