Abstract:
The cryptocurrency trading platform Bitget recently suffered a large-scale cyber attack, and more than $351 million worth of cryptocurrency was stolen from the trading platform's servers. Bitget believes that this attack is highly consistent with the known activity patterns of North Korean hacker groups. If the relevant judgment is finally confirmed, this will become the largest known cryptocurrency theft since 2026.

The attack occurred on September 24, and the attackers transferred a large amount of cryptocurrency from Bitget’s hot wallet without authorization. Hot wallets are usually connected to the Internet and are mainly used to process daily transactions. Therefore, compared with cold wallets that are offline for a long time, they themselves need to be continuously connected to the network, and therefore become an important attack target for cryptocurrency platforms.
Bitget subsequently suspended cryptocurrency withdrawals on the platform to prevent further expansion of the attack. The company said it currently has a user protection fund of about $464 million, which is theoretically enough to cover the $351 million in losses caused by the incident. However, Bitget did not announce when the withdrawal business will resume.
Bitget CEO Gracy Chen said that the attack and subsequent asset theft were highly consistent with the attack patterns of known North Korean hacker groups. However, this is currently only a judgment made by Bitget based on attack characteristics, and there is no public information to fully confirm the identity of the attacker.
A number of hacker groups linked to North Korea have long been accused of carrying out attacks against cryptocurrency exchanges, blockchain projects and related software supply chains. These organizations are believed to have obtained large amounts of funds by stealing digital assets and used some of the funds to support North Korea's nuclear weapons program.
Data from blockchain intelligence company TRM Labs shows that as of 2026, the amount of cryptocurrency theft involved in North Korea-related hacking activities accounts for approximately three-quarters of the total cryptocurrency theft in the world during the same period. If Bitget's loss is ultimately confirmed to be related to North Korean hackers, the case will further expand North Korea-related cybercrime activities to account for global cryptocurrency theft.
This incident is also the latest in a series of major hacking attacks in the cryptocurrency industry in 2026. Just earlier in September, a hacker stole approximately $340 million worth of Bitcoins from Liquid Network-related wallets and later returned most of them. In the end, approximately $47 million in assets were still under the control of the attacker.
Since the Liquid Network incident ultimately recovered most of the stolen assets, the actual scale of the loss was significantly lower than the initial stolen amount. In contrast, the $351 million involved in Bitget's incident is currently considered a direct stolen amount, and has therefore surpassed previous cases to become the largest known cryptocurrency theft so far this year.
The main targets of Bitget’s attack this time were hot wallets. Unlike cold wallets, hot wallets need to be connected to the Internet, so they can quickly process user deposits, withdrawals and transactions, but they also face higher risks of cyber attacks. Large trading platforms usually store assets in hot and cold wallets and different security facilities to reduce the risk of large-scale losses if a single system is compromised.
Bitget stated that the company is investigating the security incident and has suspended related withdrawal operations. However, as of now, the company has not announced what technical means the attacker used to enter the system, nor has it revealed which security link was breached.
Gracy Chen also did not disclose when Bitget expects to resume withdrawal services. Since the trading platform needs to confirm that the attack path has been cut off and further check wallets, accounts and related infrastructure before restoring services, the specific recovery time still depends on the progress of investigation and security fixes.
This incident once again highlights the security risks faced by cryptocurrency trading platforms. Compared with traditional financial institutions, asset transfers in cryptocurrency transactions are usually characterized by high speed, globalization, and irreversible transactions. Once an attacker successfully obtains control of a wallet, funds may be transferred to multiple addresses in a short period of time, making subsequent tracking and recovery very difficult.
At the same time, North Korea-related hacker groups have gradually expanded in recent years from direct attacks on cryptocurrency trading platforms to attacks on open source software, developers, and software supply chains. Attackers can first obtain credentials through the software supply chain or developer equipment, then further enter the enterprise's internal systems, and ultimately steal digital assets.
Bitget has not yet disclosed the complete technical details of this attack, so the specific intrusion method used by the attacker remains to be investigated. What can be confirmed at this stage is that more than $351 million in crypto assets have been transferred from Bitget hot wallets without authorization, and Bitget has suspended withdrawals and launched a security investigation.
If subsequent investigations confirm that the attack was indeed carried out by a North Korean hacker organization, then this will once again become a major case of North Korea-related cyber criminal activities obtaining cryptocurrency funds; and until the identity of the attacker and the specific intrusion path are further confirmed, Bitget's current judgment on the source of the attack is still a preliminary conclusion based on the existing attack characteristics.
Comments