---
title: Bitget reports $351 million crypto theft, suspected North Korean attack
url: https://www.dataloco.com/en/bitget-reports-351-million-crypto-theft-suspected-north-korean-attack
published: 2026-09-28T15:20:35+00:00
language: en
section: Security
source: https://www.cnbeta.com.tw/articles/tech/1579622.htm
organizations: Bitget, TRM Labs
publisher: Dataloco
---

# Bitget reports $351 million crypto theft, suspected North Korean attack

Cryptocurrency exchange Bitget reported that over $351 million in digital assets were stolen from its servers in a large-scale cyberattack. The company stated that the attack patterns align with known North Korean hacker groups, making this the largest known cryptocurrency theft of 2026 if confirmed.

The unauthorized transfer occurred on September 24, targeting Bitget's hot wallets. These wallets remain connected to the internet to process daily transactions, making them more vulnerable to network attacks than offline cold wallets. Bitget immediately suspended cryptocurrency withdrawals to prevent further asset loss. The company has not announced when withdrawal services will resume, as it must first confirm the attack path is severed and inspect its infrastructure.

Bitget CEO Gracy Chen stated that the attack and subsequent theft match the modus operandi of known North Korean hacker organizations. However, this remains a preliminary assessment based on attack characteristics, as no public information has yet fully confirmed the attackers' identity. The company is investigating the incident but has not disclosed the specific technical methods used to breach the system or which security layer was compromised.

Bitget stated it holds a user protection fund of approximately $464 million, which theoretically covers the $351 million loss. The company emphasized that it is conducting a security investigation and has paused related withdrawal operations. The timeline for restoring services depends on the progress of the investigation and security repairs.

According to data from blockchain intelligence firm TRM Labs, North Korean-linked hacker activities account for approximately three-quarters of global cryptocurrency thefts in 2026. If the Bitget incident is confirmed as a North Korean attack, it will further increase the share of North Korean cybercrime in global crypto thefts. These groups have historically targeted exchanges, blockchain projects, and software supply chains to steal digital assets, with some proceeds reportedly funding North Korea's nuclear weapons program.

This incident is the latest in a series of major cryptocurrency hacks in 2026. Earlier in September, a hacker stole approximately $340 million in Bitcoin from Liquid Network-related wallets but returned most of it, leaving about $47 million under attacker control. Because most assets were recovered in the Liquid Network case, its actual loss was lower than the initial theft amount. In contrast, the $351 million from Bitget is considered a direct loss, surpassing the Liquid Network incident as the year's largest known theft.

The event highlights the security risks facing cryptocurrency platforms. Unlike traditional financial institutions, crypto asset transfers are fast, global, and irreversible. Once attackers gain wallet control, funds can be moved to multiple addresses quickly, making tracking and recovery difficult. North Korean hacker groups have also expanded their tactics to target open-source software, developers, and supply chains, using compromised credentials to access internal systems and steal assets.

## This story in other languages

- [Nederlands](https://www.dataloco.com/nl/bitget-wordt-getroffen-door-diefstal-van-cryptovaluta-ter-waarde-van-351-miljoen-usd)
