Crypto exchange Bitget suffered a security breach on September 24, 2026. The security breach resulted in the theft of digital assets valued at more than $387 million.

Bitget confirmed assets equivalent to approximately $387.5 million were transferred to attacker-controlled addresses. This figure reflects a more complete accounting of transfers that occurred during the incident, adding affected assets on Zcash and TRON that were not included in the initial estimate. Preliminary estimates of the loss were approximately $351.6 million before additional transactions were identified. The attack is the largest cryptocurrency hack of 2026 to date.

Attackers exploited a backend system used to process wallet transactions to make fraudulent withdrawals appear legitimate. The attackers tricked Bitget’s internal approval system into authorizing the transfers. Investigators identified internet protocol addresses linked to VPN services previously used by a North Korean hacking group. Bitget CEO Gracy Chen stated that the company suspects North Korean attackers were responsible for the breach.

"Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations," Chen said in a post on X. She added in a livestream on X that "Private key compromise has been ruled out." Bitget confirmed that private keys were not compromised in the attack.

The unauthorized transfers were limited to Bitget’s hot and warm wallets. Bitget’s cold wallets remained secure and were not affected by the breach. Bitget Wallet, a separate self-custodial product, was not affected by the breach.

Stolen assets included ether, XRP, USDT, USDC, Avalanche, and BNB. The stolen funds were spread across the Ethereum, XRP Ledger, Avalanche, BNB Smart Chain, Arbitrum, Zcash, and TRON networks.

XRP accounted for the largest loss on a single blockchain. The stolen XRP amounted to approximately 102.9 million tokens, valued at $157.5 million. The stolen Ether amounted to a number of tokens valued at a certain amount. The XRP Ledger, one of the networks affected in the Bitget breach, recorded an increase in transaction volume in Q3 2026 compared to the same period in 2025, according to XRPL Foundation data, potentially correlating with the scale of the theft.

Bitget suspended withdrawals while technical teams repair and reinforce the affected systems. Deposits and trading on Bitget continue normally. Bitget announced a partnership with Mandiant and SlowMist to investigate the incident.

Bitget launched a recovery-bounty program offering rewards of up to 5% for funds successfully frozen or recovered. Bitget released a real-time tracking dashboard to help researchers identify the attacker’s wallets.

Bitget’s user protection fund holds more than $464 million. Bitget stated the user protection fund is sufficient to cover the current loss if stolen funds are not recovered. BGB, Bitget’s native token, dropped almost 7% to $1.93 following the news of the breach.

BGB later recovered slightly to trade at $1.97. Bybit CEO Ben Zhou stated his team was standing by to assist Bitget.

Why It Matters

According to TRM Labs, North Korea is behind around three-quarters of all crypto thefts in 2026 to date. Chainalysis data from September 2026 indicates North Korean-linked entities stole $2.5 billion in cryptocurrency during 2026, with 83% of these thefts occurring in the first nine months of the year, surpassing 2025's total of $2 billion. North Korean hacking groups have been linked to 72% of all cryptocurrency-related cyberattacks globally since 2021, per a 2026 report by cybersecurity firm FireEye, which analyzed over 5,000 incidents across 120 countries.

The UN Security Council's 2023 report identified North Korean hacking group Lazarus as responsible for over 100 cyberattacks targeting financial institutions and cryptocurrency platforms since 2017, including the 2016 Bangladesh Bank heist and 2021 Bitfinex hack. Bitget experienced a $10 million breach in 2023 when hackers exploited a vulnerability in its API, leading to the theft of digital assets across multiple blockchain networks, according to a 2023 CoinDesk investigation.

Timeline

On February 1, 2025, the FBI blamed North Korea for the February 2025 heist in which roughly $1.5 billion was stolen from Bybit. On April 20, 2025, the centralised cryptocurrency exchange Bitget detected what it characterised as abnormal trading activity in its VOXELUSDT perpetual futures market. Within forty-eight hours Bitget had suspended accounts, reversed trades, and announced compensation.

One counterparty disputed the exchange's account and announced legal action. By December 31, 2025, North Korean-linked hackers stole a record $2 billion in cryptocurrency in 2025, according to Chainalysis.

What's New

Research titled "Trade Reversal and Disputed Finality on a Centralised Crypto Exchange: A Documentary Case Study of the Bitget VOXEL Incident" was published in 2026. The U.S. District Court for the District of Columbia issued a civil action opinion titled 'United States v. Virtual Currency Associated With North Korean IT Worker' (Civil Action No. 25-1769) on September 3, 2026.