Skip to content

Bitget Hit by $351M Crypto Theft, North Korean Hackers Suspected

Cryptocurrency exchange Bitget was hit by a suspected cyberattack on September 24, 2026, resulting in the theft of over $351 million in digital assets. The breach, attributed to North Korean hackers, is the largest crypto theft of the year and highlights the growing threat of state-backed cybercrime in the digital assets sector. Bitget has suspended withdrawals but assured users that its $464 million User Protection Fund will cover the losses.

By

Editor, LazyFounders

Published 6 min read
Bitget Hit by $351M Crypto Theft, North Korean Hackers Suspected
Image: Image Credits:Samuil Levich / Getty Images via source

Cryptocurrency exchange Bitget was hit by a suspected cyberattack on September 24, 2026, resulting in the theft of over $351 million in digital assets. The breach, attributed to North Korean hackers, is the largest crypto theft of the year and highlights the growing threat of state-backed cybercrime in the digital assets sector. Bitget has suspended withdrawals but assured users that its $464 million User Protection Fund will cover the losses.

30 SEC SUMMARY

  • North Korean hackers are suspected of stealing over $351 million in cryptocurrency from Bitget, marking the largest crypto theft of 2026.
  • The breach targeted Bitget’s hot and warm wallets but did not affect cold wallets or its self-custodial Bitget Wallet.
  • Bitget suspended withdrawals but assured users that its $464 million User Protection Fund will cover the losses.
  • Investigators, including Mandiant and SlowMist, are probing the incident, with no evidence of private-key compromise or insider involvement.
  • North Korea is linked to around 75% of all crypto thefts in 2026, with total losses exceeding $1 billion this year.

TABLE OF CONTENTS

  • Bitget Hit by Largest Crypto Theft of 2026
  • North Korean Hackers Suspected
  • Response and Investigation
  • Broader Implications for Crypto Security
  • Context on North Korean Cybercrime
  • What this means
  • Key takeaways
  • FAQ
  • Sources

KEY HIGHLIGHTS

  • Bitget suspended withdrawals after a $351.6 million theft from its hot and warm wallets on September 24, 2026.
  • Investigators suspect North Korean hackers, who are linked to 75% of all crypto thefts in 2026.
  • The breach did not affect Bitget’s cold wallets or its self-custodial Bitget Wallet app.
  • Bitget’s $464 million User Protection Fund will cover the losses, ensuring user funds remain secure.
  • The attack exploited backend systems, not private keys, highlighting new vectors for crypto heists.

Bitget Hit by Largest Crypto Theft of 2026

Cryptocurrency exchange Bitget suffered a suspected cyberattack on September 24, 2026, resulting in the theft of over $351 million in digital assets. The incident is the largest crypto theft of the year, surpassing a $340 million hack earlier in September.

According to The Next Web and TechCrunch, the breach targeted Bitget’s hot and warm wallets but did not compromise its cold wallets. The company detected unauthorized transfers at 18:31 UTC, prompting an immediate suspension of withdrawals. Bitget stated that its $464 million User Protection Fund will cover the losses, ensuring user funds remain unaffected.

North Korean Hackers Suspected

Investigators suspect North Korean hackers, specifically the Lazarus Group, a label used by Western governments for state-backed cybercrime operations linked to Pyongyang. Blockchain intelligence firm TRM Labs reports that North Korea is responsible for approximately 75% of all cryptocurrency thefts in 2026 so far, with total losses exceeding $1 billion.

The attacker used fake transfer data to move funds, swapping most of the stolen assets—including Ether, XRP, BNB, AVAX, USDT, and USDC—into 67,982 Ether, valued at around $183 million. On-chain investigators traced IP addresses to VPN services previously associated with North Korean hacking groups.

Response and Investigation

Bitget has enlisted cybersecurity firms Mandiant and SlowMist to conduct an independent investigation into the breach. The company assured users that deposits and trading remain operational, with a withdrawal resumption plan expected by September 26. Law enforcement has been notified, and Bitget has ruled out private-key compromise or insider involvement as the cause of the attack.

The company’s self-custodial Bitget Wallet, which operates on separate infrastructure, was not affected by the incident. Bybit CEO Ben Zhou offered support, noting his exchange’s readiness to assist Bitget in mitigating the fallout.

Broader Implications for Crypto Security

This incident is the latest in a series of high-profile crypto thefts attributed to North Korean hackers, who have increasingly targeted open-source software and developed AI tools to bypass security measures. U.S. officials indicate that such thefts are used to fund North Korea’s government and nuclear weapons program.

The breach highlights vulnerabilities in hot and warm wallet systems, even among well-funded exchanges. It also underscores the need for continuous advancement in security protocols, including real-time monitoring and threat intelligence-sharing across the industry.

Context on North Korean Cybercrime

North Korean state-backed hackers, particularly the Lazarus Group, have been a dominant force in cryptocurrency thefts for years. Their operations are often characterized by sophisticated attack vectors, including phishing, supply-chain exploits, and AI-driven tools to circumvent security safeguards.

In 2026 alone, North Korea has been linked to multiple major crypto heists, including a $285 million theft from Drift and a $1.5 billion attack on Bybit in February 2025. These incidents reflect a broader trend of state-sponsored cybercrime targeting the digital assets sector.

What this means

LazyFounders analysis — our interpretation, not reported fact.

This incident underscores the escalating sophistication of state-backed cyber threats in the cryptocurrency space, particularly those linked to North Korea. For founders and operators in the digital assets industry, the attack is a stark reminder of the vulnerabilities inherent in hot and warm wallet systems, even when robust security measures are in place.

Bitget’s response—suspension of withdrawals, transparent communication, and reliance on a user protection fund—sets a benchmark for crisis management in the sector. However, the fact that the attack exploited backend systems rather than private keys suggests that exchanges must continuously evolve their security protocols beyond traditional safeguards.

The concentration of crypto thefts attributed to North Korean hackers also highlights the need for collaborative industry efforts, including intelligence-sharing and advanced threat detection, to mitigate such risks. For smaller exchanges or startups, this incident may serve as a wake-up call to prioritize security infrastructure and contingency planning, as even well-funded platforms are not immune to large-scale breaches.

Key takeaways

  • North Korean hackers are suspected of stealing over $351 million from Bitget, the largest crypto theft of 2026.
  • The breach targeted Bitget’s hot and warm wallets but did not compromise cold wallets or its Bitget Wallet app.
  • Bitget has paused withdrawals and will use its $464 million User Protection Fund to cover losses.
  • Investigations by Mandiant and SlowMist suggest no private-key compromise or insider involvement.
  • North Korea is responsible for approximately 75% of all crypto thefts in 2026, with total losses surpassing $1 billion.

FAQ

What was stolen in the Bitget hack?

The stolen assets included Ether, XRP, BNB, AVAX, USDT, USDC, and tokenized gold, totaling over $351 million.

How did Bitget respond to the breach?

Bitget suspended withdrawals, informed law enforcement, and enlisted cybersecurity firms Mandiant and SlowMist for an independent investigation. The company stated that its User Protection Fund will cover the losses.

Who is suspected of the Bitget hack?

Investigators suspect North Korean hackers, specifically the Lazarus Group, which is linked to approximately 75% of all crypto thefts in 2026.

Were Bitget’s cold wallets affected?

No, the breach only affected Bitget’s hot and warm wallets. Cold wallets and the self-custodial Bitget Wallet remained secure.

How common are crypto thefts linked to North Korea?

North Korea is responsible for around three-quarters of all crypto thefts in 2026, with total losses exceeding $1 billion this year alone.

Related on LazyFounders

Sources

  1. TechCrunch · 2026-09-25
    North Korean hackers suspected in $351M crypto theft, the largest so far this year
  2. The Next Web · 2026-09-25
    Bitget suspects North Korean hackers in $351.6m theft from its hot wallets
  3. Gizmodo · 2026-09-25
    North Korea ‘Very Likely’ Behind $388 Million Hack of Crypto Exchange Bitget

This story is an original summary drafted with AI by LazyFounders from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are LazyFounders's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.

Get the LazyFounder Brief

Startup, funding and AI news in a five-minute read. Join the early-access list.

Lazy Founder - Powered by Blogy.in