Cryptocurrency exchange Bitget has disclosed that suspected North Korean threat actors stole $351.6 million from its hot and warm wallets on September 24, 2026. The company detected unauthorized transfers at 18:31 UTC and immediately suspended withdrawals, though deposits and trading continue to operate normally. Bitget emphasized that cold wallets and the vast majority of platform assets remain secure, and customer account balances are accurate.
According to Bitget CEO Gracy Chen, the attacker compromised a critical backend system within the wallet infrastructure, spoofed transaction data, and triggered the authorization process to move funds. Affected assets include ETH, XRP, BNB, AVAX, USDT, and USDC across multiple chains, including Ethereum, Arbitrum, and Base. Chen stated that some blockchain foundations have already confirmed freezing hacker wallet addresses.
Both sources agree on the stolen amount and the suspected North Korean origin, citing IP behavior patterns and on-chain analysis. However, neither source provides specific technical details of the intrusion, which remains under active investigation. Bitget has enlisted Google-owned Mandiant and SlowMist for a third-party review, and the company notes that its self-custodial Bitget Wallet was not affected. This incident follows a recent wave of North Korean-linked crypto heists, including the $1.5 billion Bybit theft attributed to the TraderTraitor group.