The September 24, 2026 Bitget breach involved approximately $387.5 million stolen from hot and warm wallets after attackers exploited vulnerabilities in third-party software, obtained internal credentials and manipulated withdrawal authorization processes. Chainalysis attributed the activity to North Korea-linked actors, saying the theft pushed crypto stolen by such groups above $1 billion in 2026, although Bitget said specific attribution remains unconfirmed and investigations continue. Bitget said cold wallets and private keys remained secure, used its User Protection Fund to cover customer losses, and restored withdrawals in stages between September 28 and October 2. The fund, valued at more than $464 million before the breach, fell below $200 million after the loss and was replenished to $309 million, or about 3,705 BTC, by September 30. A September 29 proof-of-reserves report showed 131% overall asset coverage, including 142% for Bitcoin and 110% for Ethereum. Attackers moved assets through cross-chain protocols, instant swaps and laundering services, including transfers into Zcash's Ironwood shielded pool. NEAR Intents halted more than $50 million in attempted laundering but froze about $503,000, while Circle and Tether froze approximately $318,000 in related stablecoins. THORChain declined Bitget CEO Gracy Chen's request to block attacker addresses and processed $678 million in trading volume during the two days after the breach, well above its usual daily range.