Crypto exchange Bitget says North Korea is very likely behind a theft of about $387.5 million that did not require anyone to steal the keys to the vault.
Security systems at the Seychelles-based platform flagged unauthorized transfers from some of its hot wallets at 18:31 UTC on Thursday, according to an official incident notice and a post from CEO Gracy Chen. The breach reached parts of Bitget’s hot and warm wallet layers. Cold wallets, which sit offline, were not hit. To be clear, the hack only affected Bitget Exchange. Bitget Wallet users were not affected.
At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately.
Chen later said investigators had ruled out a private-key compromise. “The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” she wrote on X. In other words, the payouts looked legitimate to Bitget’s internal system. Bitget said the investigation is continuing with assistance from Mandiant and SlowMist.
6 million and did not publish a token-by-token inventory. 75 million), then USDT, USDC, USDT0, 3,000 XAUt of tokenized gold, BNB, AVAX, and TRX. Lookonchain also said the attacker had already swapped most of the EVM-chain proceeds into 67,982 ETH. 5 million. It said the revision is a fuller accounting of transfers during the incident, not more theft after the outflow was contained. Arkham Intelligence has tagged the hacker’s wallet on its blockchain intelligence platform.
Source link







