North Korean Hackers “Very Likely” Drained $350 Million From Bitget, CEO Says

BeInCrypto
Ouvrir sur BeInCrypto
North Korean Hackers “Very Likely” Drained $350 Million From Bitget, CEO Says

Bitget CEO Gracy Chen said North Korea was "very likely" behind the $350 million Bitget hack. The attackers breached a backend system and never obtained private keys, she added.

Withdrawals remain suspended after the September 24 breach. DefiLlama data now ranks it as the largest crypto hack of 2026.

Chen Follows a VPN Trail to North Korea

Chen addressed the hack during a live Q&A on X after the incident. She pointed to the Democratic People's Republic of Korea (DPRK).

“But we've identified some IP addresses that match the VPN choices by a certain DPRK group. So we think this is very likely to be attacked by North Korean,” she said.

Chen did not name the group. However, on-chain analyst Specter said the stolen XRP (XRP) was bridged and links directly to AFX Trade exploit funds. 

AFX lost about $24 million in July. Specter noted that the attack had been attributed to TraderTraitor, a Lazarus-linked unit. LayerZero tied the KelpDAO bridge exploit to the same unit in April.

Follow us on X to get the latest news as it happens

Regarding who is behind the hack:

I present to you THE LAZARUS GROUP.

just linked this hack to the AFX hack, which stole M in July and was specifically attributed to TraderTraitor.

The stolen XRP from Bitget was bridged and can be directly linked to the funds stolen in the… https://t.co/3CgWFaXF1i pic.twitter.com/cRPdhhdpjQ

— Specter (@SpecterAnalyst) September 25, 2026

How the Bitget Hack Bypassed Private Keys

Chen said the hackers never obtained private keys for Bitget's hot, warm, or cold wallets. They also did not fake user withdrawal requests. Her later post described the method in more detail.

“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” she explained.

She said losses are contained, and no further unauthorized transfers can occur. Lookonchain's breakdown shows the attackers took 9 different assets.

XRP made up the largest share, with about 102.9 million tokens worth roughly $157.5 million. Bitget's confirmed loss is about double the roughly $176 million seen in initial on-chain reports.

The exchange says its User Protection Fund, now above $464 million, covers the full loss.

BITGET HAS A 4M EMERGENCY FUND FOR HACKS

The exchange holds around 5,500 BTC in its Protection Fund, designed to cover users in case of hacks or stolen assets. Bitget launched the fund in 2022 and previously committed to keeping it above 0M.

At the end of August, it held… https://t.co/RmyH9VeseG pic.twitter.com/RNkAEo7jyk

— BeInCrypto (@beincrypto) September 24, 2026

The Biggest Crypto Heist of 2026 Lands at Bitget

DefiLlama data ranks the Bitget theft as the largest crypto hack of 2026 so far. It edges out Liquid Network's $320 million incident in September and the $295 million Drift breach in April.

The tracker logs about $2.2 billion lost across 281 incidents this year. Bitget alone accounts for roughly 16% of that total. The incident also makes September the costliest month of 2026 so far, ahead of April's roughly $648 million.

North Korean groups drove most of 2026's early losses. TRM Labs found they accounted for 76% of crypto hack losses through April, mostly via the Drift and Kelp attacks. In 2025, Lazarus carried out the $1.5 billion Bybit hack, the year's largest.

Chen has promised a full technical report once investigators confirm how the intrusion happened. That report should show whether forensic evidence backs the North Korea attribution. 

Subscribe to our YouTube channel to watch leaders and journalists provide expert insights

https://youtu.be/KQybhNRlPaU

Read the Original story North Korean Hackers “Very Likely” Drained $350 Million From Bitget, CEO Says by Kamina Bashir at beincrypto.com