---
title: "Bitget Loses $351.6M in Hot Wallet Breach Linked to North Korea"
description: "Attackers manipulated backend authorization data across seven networks in the largest crypto theft of 2026, though Bitget says its $464 million reserve covers the balance."
url: https://basisdesk.news/news/bitget-hot-wallet-breach-351m-north-korea
published: 2026-09-30T19:56:11.811Z
modified: 2026-09-30T19:56:11.811Z
section: Security & Hacks
author: Basis Desk Newsroom (AI-generated, source-verified)
sentiment: bearish
tickers: [BTC, ETH, XRP, TRX]
tags: [bitget, hacks, north-korea, trm-labs, hot-wallets]
license: Quote with attribution to Basis Desk (basisdesk.news). Not financial advice.
---

# Bitget Loses $351.6M in Hot Wallet Breach Linked to North Korea

Attackers manipulated backend authorization data across seven networks in the largest crypto theft of 2026, though Bitget says its $464 million reserve covers the balance.

## Key points

- Bitget suffered a $351.6M breach across seven chains on Sept. 24, making it the largest crypto heist of 2026 so far.
- The attacker manipulated internal authorization data to trigger hot and warm wallet transfers without stealing private keys.
- On-chain laundering patterns directly overlap with North Korean hacking syndicate TraderTraitor, though TRM has not formally attributed the attack.

## Editorial remark

- **Context:** The incident mirrors the February 2025 Bybit breach, where attackers bypassed cryptography altogether by compromising internal approval interfaces rather than stealing private keys directly.
- **Impact:** Bitget maintains its $464 million protection reserve covers user losses, but the incident adds to more than $690 million already attributed to North Korean state hackers in 2026.
- **Watch:** Release of Bitget's comprehensive forensic incident report and movement of the dormant ETH and XRP wallets holding the bulk of the stolen funds.

Cryptocurrency exchange Bitget lost an estimated $351.6 million on Sept. 24 after attackers compromised its backend systems to siphon funds from hot and warm wallets, according to blockchain analytics firm TRM Labs [1]. The breach spans seven networks, including Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain, and Base [1]. Bitget identified the illicit activity at 18:31 UTC, halted withdrawals, and confirmed its cold storage remained untouched [1]. At the time of writing, major crypto markets held flat, with $BTC trading at $83,488 and $ETH at $2,668.

According to Bitget CEO Gracy Chen, the intrusion did not involve stolen private keys [1]. Instead, the perpetrator accessed an internal backend system tied to wallet controls, spoofed transaction parameters, and tricked the exchange's authorization process into approving the unauthorized outflows [1]. Early industry estimates pegged the theft at $170 million to $190 million by examining EVM networks alone, but on-chain data logged an additional $158 million in $XRP and $7 million in $TRX [1]. Bitget stated that its $464 million User Protection Fund will fully absorb the balance [1].

## Laundering Footprint Points to TraderTraitor

Chen noted that North Korean involvement is "very likely," citing internal telemetry linking connecting IP addresses to VPN infrastructure tied to state-sponsored hackers [1]. While TRM Labs has stopped short of formal attribution, the firm revealed that the laundering network moving Bitget's assets overlaps directly with infrastructure deployed in previous North Korean operations, including the February 2025 Bybit breach and the AFX Bridge heist [1]. On-chain trackers have not seen this specific laundering network operate with any other syndicate, pointing toward the North Korean threat group TraderTraitor [1].

Following the incident, the stolen assets were rapidly fractured into round balances—primarily 10,000 $ETH and 20 million XRP increments—across newly generated addresses, where the vast majority remained stationary through the morning of Sept. 25 [1]. Portions on BNB Chain and TRON were converted into Bitcoin via THORChain, SunSwap, and cross-chain routing services [1]. If formal attribution confirms Pyongyang's role, North Korean crypto theft in 2026 would surpass $1 billion, trailing only 2025's historic totals [1].

## FAQ

**Were private keys compromised in the Bitget breach?**

No. Bitget reported that private keys were not stolen; rather, an attacker penetrated backend systems to spoof transaction approval data.

**Are customer funds at Bitget protected?**

Bitget stated that its cold storage was unaffected and that its $464 million User Protection Fund covers the entire $351.6 million loss.

**Has the attack been definitively attributed to North Korea?**

Bitget called North Korean involvement very likely based on VPN IP links, and TRM Labs verified laundering overlaps with TraderTraitor networks, though technical attribution remains ongoing.

## Sources

1. [Bitget Loses USD 351.6 Million in Hot Wallet Breach in Likely North Korea Attack](https://www.trmlabs.com/resources/blog/bitget-loses-usd-3516-million-in-hot-wallet-breach-in-likely-north-korea-attack) — trmlabs.com, 2026-09-30

---
Basis Desk Newsroom · AI-generated, source-verified · https://basisdesk.news/about/how-we-use-ai
