Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

Дата публикации: 25-09-2026 10:35:55

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets. 
"At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," Bitget said in a post shared on X. "Bitget's cold wallets and the overwhelming majority of platform assets remain

Основное содержимое страницы с новостью.

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets. 

"At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," Bitget said in a post shared on X. "Bitget's cold wallets and the overwhelming majority of platform assets remain secure and unaffected."

The company emphasized that customer account balances remain accurate, and deposits and trading continue to operate normally. However, withdrawals have been temporarily suspended out of an abundance of caution while a "comprehensive security review" is underway.

Bitget did not disclose any details on how the attack took place, but said it has enlisted the help of Google-owned Mandiant and SlowMist for a third-party investigation.

"Bitget Wallet operates as a self-custodial wallet on a completely separate and independent infrastructure from Bitget Exchange and was not affected by this incident," it noted.

According to Bitget CEO Gracy Chen, assets impacted by the hack include ETH, XRP, BNB, AVAX, USDT, and USDC, with the chains involving Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base.

"We have contacted the foundations of all affected chains, and some foundations have confirmed the freezing of hacker wallet addresses," Chen said. "Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations."

"The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation."

The development comes about a week after SentinelOne attributed the North Korea-linked TraderTraitor group to an attack targeting an India-based information technology (IT) services company. TraderTraitor is best known for the theft of $1.5 billion from Bybit and $292 million from KelpDAO's LayerZero bridge.

Update

In a follow-up post on X, Bitget said assets equivalent to approximately $390.06 million were transferred to attacker-controlled addresses across multiple networks following the hack, citing "latest on-chain tracing and classification of transactions."

The crypto exchange has also launched a Recovery Bounty Program to "mobilize exchanges, blockchain projects, security researchers, investigators and the wider on-chain community to assist with freezing and recovering affected assets."

"Connections between XRP from the Bitget exploit and ETH from a previous DPRK-attributed exploit have been observed," Elliptic said, it also spotted "connections between stolen Bitget funds and addresses involved in the laundering of previous DPRK-attributed exploits, including the exploit of Bybit in 2025."

"Shared laundering infrastructure between incidents is a recurring feature in the laundering of DPRK-attributed hacks, with launderers prioritizing speed over operational discipline," Elliptic added.

TRM Labs has also uncovered multiple overlaps with wallets used to launder previous North Korean hacks, including Bybit and AFX Bridge, stating the overlaps point to the involvement of TraderTraitor.

If the Bitget theft turns out to be the work of North Korea, 2026 would become the second-largest year on record for North Korean crypto theft, reaching $1.04 billion, behind 2025's $1.68 billion.

"North Korea keeps stealing from this ecosystem at alarming speed and scale," Ari Redbord, Global Head of Policy at TRM Labs, said in a statement. "We have to harden cyber controls across the industry, and we also have to go after these actors offensively, using every national security authority we have."

Bitget Fixes Security Flaw Exploited in Hack

In a post shared on X on September 26, 2026, Bitget said it will resume withdrawals in orderly phases starting on September 28, 2026, at 8 a.m. UTC, adding the vulnerability involved in the incident has been identified and addressed.

"The incident remains contained, and no further unauthorized transfers are possible," Bitget added. "User funds are unaffected throughout this process. Trading and deposits continue to operate."

According to a real-time fund tracing dashboard published by Coindesk, Circle and Tether have frozen stablecoins worth $339,100 linked to the hack.

(The story was updated after publication to include additional insights from Elliptic and TRM Labs.)

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M010.1928-09-2026
2У Bitget украли криптовалюту на $352 млн Одна из крупнейших ...08.3627-09-2026
3У Bitget украли криптовалюту на $352 млн Одна из крупнейших ...08.3627-09-2026
4Bitget 被盗走价值 3.875 亿美元加密货币031.1327-09-2026
5Хакеров Bitget начали грабить свои же обменники016.2529-09-2026
6Ethereum стал тайником для управляющих серверов хакеров КНДР015.2629-09-2026
7⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats012.1228-09-2026
8Хакеры похитили данные 67 000 владельцев аппаратных кошельков Trezor013.2407-09-2026
9Фигуранты дела о фиктивных браках с бойцами СВО похитили около 35 млн рублей018.9528-09-2026
10THORChain отказался блокировать адреса хакеров, связанных со взломом Bitget05.8228-09-2026

Классификация: Экономика. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 11.29. Источник: thehackernews.com.