deniz.in

Markets

Weather

Loading weather

· via TechCrunch

Bitget loses $351M as suspected North Korean hackers spoof its own approval process

Suspected North Korean operators compromised a Bitget backend, fed forged transaction data to its own approval process and moved $351.6 million out of hot and warm wallets — the largest crypto theft of 2026 so far.

Bitget loses $351M as suspected North Korean hackers spoof its own approval process

What happened

Cryptocurrency exchange Bitget says attackers drained $351.6 million from its wallets on September 24, 2026, in what is the largest known crypto theft of the year so far. According to TechCrunch, the heist eclipses a $340 million theft earlier in September, in which the attacker ultimately returned all but $47 million.

Bitget's security systems flagged unauthorized transfers at 18:31 UTC on September 24, according to the exchange's public statements as reported by The Hacker News and analyzed by RedEye Threat Intelligence. TechCrunch puts the total at more than $351 million. The funds left hot wallets — the internet-connected wallets used for active trading — and warm wallets, according to the exchange. Bitget says its cold wallets and the overwhelming majority of platform assets were not affected.

A spoofed approval process

The size of the loss is only half the story. According to Bitget chief executive Gracy Chen, the attacker "compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out."

No private key is reported stolen and no signer is reported compromised. The approval workflow ran as designed — it simply approved transactions assembled from forged data produced by a system it trusted.

The stolen assets include ETH, XRP, BNB, AVAX, USDT and USDC spread across seven networks: Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base.

Chen said the operation was "highly consistent with known patterns of North Korean hacker organizations," citing IP behavior and on-chain analysis, though Bitget has not named a specific group. According to TechCrunch, blockchain intelligence firm TRM Labs attributes roughly three-quarters of all crypto stolen in 2026 to date to North Korean actors, collectives suspected of funding the country's nuclear weapons program.

Containment and open questions

Bitget has suspended withdrawals pending a comprehensive security review, while deposits, trading and customer balances continue normally, according to The Hacker News. Mandiant and SlowMist are running a third-party investigation, and Bitget has contacted the foundations behind each affected chain — RedEye reports that some have already frozen attacker addresses. The exchange's self-custodial Bitget Wallet product runs on separate infrastructure and was not affected.

TechCrunch reports that Bitget holds $464 million in its user protection fund, which the company says should cover the cost of the theft.

Plenty remains unknown. Bitget has not disclosed the initial access vector, which backend system was compromised, how long the attacker was inside, or how much of the stolen money has been frozen.

A familiar pattern

The Hacker News notes that the disclosure came about a week after SentinelOne attributed an attack on an India-based IT services company to TraderTraitor, a North Korea-linked group best known for the $1.5 billion Bybit theft and a $292 million attack on KelpDAO's LayerZero bridge. Bitget has not linked its incident to any named group.

The broader trend, as RedEye frames it, is that the costliest crypto thefts no longer rely on breaking cryptography. They target the systems around the signing step: the backend that prepares transactions, the interface that displays them, and the vendors and IT providers that can reach both. The key stays safe while the attacker controls what it signs.

Why it matters

The failure mode applies well beyond crypto. Payment runs, vendor bank-detail changes, release approvals and privileged-access workflows are all approval chains that trust an upstream system to describe the action correctly. When one compromised host can change both the transaction and its description, the approval only confirms that the data is internally consistent.

RedEye's recommendations for defenders: verify destination addresses against allowlists held on separate infrastructure with separate admin credentials, reconcile every outbound transfer against a request created before signing, cap losses with velocity limits enforced at the signer rather than in the backend, and treat IT service providers as part of the wallet perimeter. Until Mandiant and SlowMist publish their findings, other exchanges have to assume the same technique could still work against them.

  • #crypto
  • #security
  • #bitget
  • #north-korea
  • #blockchain

Related posts