Skip to content
Skip to content

Independent e-magazine

the OUTSPOKEN digest

Suspected North Korean Hackers Stole Nearly $390 Million From the Bitget Exchange, the Largest Crypto Theft of the Year

Attackers compromised a backend system and manipulated transaction data to trick Bitget's own approval process into moving funds out of its hot wallets, pushing North Korea's 2026 crypto haul past a billion dollars.

Outspoken Digest Markets Desk

Saturday, September 26, 2026/2 min read

A bitcoin coin, illustrative of the cryptocurrency stolen in the Bitget breach and not the exchange itself, photographed in September 2022
Photo: Satheesh Sankaran via Wikimedia Commons (CC BY-SA 2.0)

Bitget, a major cryptocurrency exchange, said suspected North Korean hackers stole roughly 351.6 million dollars from its hot and warm wallets in an attack its security systems first detected on 24 September at 18:31 UTC, a figure later revised upward to around 387.5 million dollars once transfers on the Zcash and TRON networks were fully accounted for. The Hacker News's report describes it as the largest single crypto theft of 2026 so far, and one that pushes North Korea's cumulative haul from digital asset thefts this year above one billion dollars.

How the attackers got in

The intrusion did not rely on stealing Bitget's private keys directly. Instead, according to blockchain analytics firm TRM Labs, whose analysis of the breach traces the mechanics in detail, attackers compromised a backend system and manipulated the transaction data displayed to Bitget's own authorisation process, tricking it into approving transfers that looked legitimate to the systems meant to catch exactly this kind of theft. Bitget has said its cold wallets, which hold the large majority of customer assets and are kept offline specifically to resist this style of attack, remain secure and unaffected.

A pattern with a familiar signature

The attribution to North Korea rests on the operational pattern seen across a string of exchange hacks attributed to state-linked groups over recent years, including the tactic of manipulating backend approval systems rather than attempting a more conspicuous direct breach of cold storage. North Korean state hacking units have used stolen cryptocurrency for years as a way to fund the country's weapons programmes while circumventing international sanctions on its conventional financial system, and blockchain trackers have watched the country's cumulative crypto theft total climb steadily through 2026 even as exchanges have invested heavily in the kind of cold storage protections that are supposed to make attacks like this one far harder to pull off.

Bitget's response

Bitget has temporarily suspended withdrawals while it conducts what it describes as a comprehensive security review, a standard precaution after a breach of this scale that nonetheless leaves ordinary customers unable to move their own funds in the interim. The exchange has not said when withdrawals will resume, and the incident is likely to renew pressure on exchanges generally to explain why backend authorisation systems, rather than the cold wallets they are built to protect, keep proving to be the weak point that determined, well-resourced attackers go looking for first.

Published in The Outspoken Digest

Editorial desk

Outspoken Digest Markets Desk

Reports for The Outspoken Digest across Crypto, Business.

Newsletter

The Digest, in your inbox

One edition, sent when it is ready. No noise, and your address is never passed on.

We send a confirmation first. One click to leave, always.

Share this story

the OUTSPOKEN digest

Beyond boundaries. Independent stories on technology, culture, and the trends shaping how we live.