$ techbeacon▋
Threats

Bitget Reports $351.6 Million Theft Linked to Suspected North Korean Hackers

Bitget Reports $351.6 Million Theft Linked to Suspected North Korean Hackers

Cryptocurrency exchange Bitget disclosed that attackers believed to be linked to North Korea siphoned roughly $351.6 million from its hot and warm wallets after breaching the platform's backend infrastructure.

The breach was first detected at 18:31 UTC on September 24, 2026, when Bitget's security monitoring flagged unauthorized transfers involving a limited set of hot wallets. The exchange confirmed that the illicit movement of funds was confined to both hot wallets, used for immediate transaction processing, and warm wallets, which serve as short‑term reserves.

Hot and warm wallets are integral to the liquidity and operational flow of crypto platforms, but they also present attractive targets for cybercriminals because they hold assets that can be moved quickly. Bitget said the compromise appears to have stemmed from a backend vulnerability, though it has not released technical details about the exact exploit used.

North Korean cyber units have a documented history of targeting cryptocurrency services to generate revenue for the regime, often employing sophisticated phishing, malware, and supply‑chain attacks. While Bitget has not identified a specific group, the attribution aligns with patterns observed in previous state‑linked operations that have drained digital assets from exchanges and individual wallets worldwide.

The incident underscores ongoing concerns about the security of crypto exchanges, especially as the market expands and regulatory scrutiny intensifies. Industry observers note that the loss of more than $350 million in a single event could prompt tighter compliance requirements, heightened audits of wallet management practices, and greater collaboration between exchanges and law‑enforcement agencies.

Bitget has pledged to cooperate with investigators and to implement additional safeguards to prevent future incidents. The exchange is also working to reimburse affected users, though the timeline for restitution remains unclear. As authorities trace the flow of the stolen funds, the case may become a benchmark for how the crypto sector responds to state‑sponsored cyber threats.

Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related