Bitget hack pushes North Korea-linked crypto theft above $1 billion in 2026

  • Bitget used its Protection Fund to cover approximately $387.5 million stolen on September 24, 2026.
  • Bitget rebuilt its Protection Fund to $309 million by September 30 after it fell below $200 million.
  • Bitget restored withdrawals from September 28 through October 2, while limited stolen funds were frozen.

The September 24, 2026 Bitget breach involved approximately $387.5 million stolen from hot and warm wallets after attackers exploited vulnerabilities in third-party software, obtained internal credentials and manipulated withdrawal authorization processes. Chainalysis attributed the activity to North Korea-linked actors, saying the theft pushed crypto stolen by such groups above $1 billion in 2026, although Bitget said specific attribution remains unconfirmed and investigations continue. Bitget said cold wallets and private keys remained secure, used its User Protection Fund to cover customer losses, and restored withdrawals in stages between September 28 and October 2. The fund, valued at more than $464 million before the breach, fell below $200 million after the loss and was replenished to $309 million, or about 3,705 BTC, by September 30. A September 29 proof-of-reserves report showed 131% overall asset coverage, including 142% for Bitcoin and 110% for Ethereum. Attackers moved assets through cross-chain protocols, instant swaps and laundering services, including transfers into Zcash's Ironwood shielded pool. NEAR Intents halted more than $50 million in attempted laundering but froze about $503,000, while Circle and Tether froze approximately $318,000 in related stablecoins. THORChain declined Bitget CEO Gracy Chen's request to block attacker addresses and processed $678 million in trading volume during the two days after the breach, well above its usual daily range.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.