ThreatPaper
Cryptocurrency & Web3Financial FraudHigh

Bitget: a backend compromise, not a stolen key, drains ~$387.5M via spoofed transfers

By Sethu Satheesh · 29 Sept 2026 · 11 min read

Threat Actor: Unconfirmed; suspected North Korea-linked actor (per Bitget) · Target: Bitget cryptocurrency exchange (hot and warm wallets)

Source: www.coindesk.com


Executive Summary

On September 24, 2026, at 18:31 UTC, the cryptocurrency exchange Bitget's monitoring systems flagged a burst of unauthorized transfers leaving a limited set of its hot wallets.12 The exchange initially put the loss at $351.6 million; over the following days, as stolen assets were traced onto additional chains including Zcash and TRON, Bitget revised the figure upward to roughly $387.5 million.23 It is, on the numbers reported, the largest disclosed cryptocurrency theft of 2026 to date.4

What makes this incident notable is not the size but the method. Bitget's chief executive, Gracy Chen, was explicit that this was not a stolen-key theft: "Private key compromise has been ruled out."5 Instead, she said, "the attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out."5 Chen's own analogy was that it was "the digital version of slipping forged withdrawal slips through a bank's own teller window" — the attackers did not forge a signature, they got into the system that prepares and submits transfer requests and fed the exchange's own approval workflow paperwork that looked legitimate.5 The authorization machinery processed the forged requests as real, and funds drained from the hot and warm wallets. The cold wallets, and the separate self-custodial Bitget Wallet product, were untouched.15

The attribution is suspected, not confirmed. Chen described the intrusion as "highly consistent with known patterns of North Korean hacker organizations," citing IP behaviour patterns and on-chain analysis; no government or independent body had publicly confirmed a DPRK link as of this writing.14 The broader context is real — the blockchain-intelligence firm TRM Labs assesses that North Korea is behind roughly three-quarters of all cryptocurrency thefts in 2026 to date — but that is a statement about the year, not a forensic finding about this specific heist.4

For users, the practical outcome was contained. Bitget halted all withdrawals on discovery, said the entire loss fell within its User Protection Fund (which holds over 5,500 BTC, worth roughly $464 million), and began a phased resumption of withdrawals on September 28, 2026, at 08:00 UTC after identifying and addressing the vulnerability.12 Customer balances, the exchange said, were untouched. The engagement of Mandiant and SlowMist alongside law enforcement to run the forensics is the part still in progress; the exact intrusion vector into the backend system has not been publicly disclosed.1

Verification of Claims

  1. Claim: North Korean hackers stole the funds from Bitget. → Assessed, not confirmed → The only attribution on record is Bitget CEO Gracy Chen's statement that the breach is "highly consistent with known patterns of North Korean hacker organizations," based on IP behaviour and on-chain analysis. No government or independent forensic body has publicly confirmed DPRK involvement in this specific incident; TRM Labs' figure that North Korea is behind ~75% of 2026 crypto theft is context, not case-specific evidence.145

  2. Claim: Bitget lost $351.6 million. → Superseded → $351.6 million was the initial figure Bitget disclosed and the number most headlines repeated. Bitget subsequently revised the loss upward to approximately $387.5 million as stolen assets were traced onto Zcash and TRON. The $351.6M figure is not wrong so much as an early, incomplete count.23

  3. Claim: The attackers did not compromise Bitget's private keys. → Verified (per Bitget) → CEO Gracy Chen stated directly that "private key compromise has been ruled out," and described the mechanism as a compromise of the backend system that prepares and submits transfers, which was used to spoof transaction data and drive the authorization process. This is the exchange's own finding; the independent forensics by Mandiant and SlowMist were still ongoing.15

  4. Claim: This is the largest cryptocurrency theft of 2026 so far. → Weak evidence → The "largest of the year" framing is asserted by reporting rather than sourced to an independent tally, and the loss figure itself moved from $351.6M to ~$387.5M during the disclosure. It is plausibly true — it eclipses a ~$340M September incident — but rests on an unverified running total, so it should be read as a strong likelihood, not a confirmed record.24

Timeline

Date / time (UTC) Actor Event Source
September 24, 2026, 18:31 Bitget Monitoring systems flag unauthorized transfers from a limited set of hot wallets 12
September 24, 2026 Bitget All withdrawals suspended; investigation opened with Mandiant, SlowMist and law enforcement; initial loss stated at $351.6M 1
September 24–25, 2026 Gracy Chen (CEO) Confirms hack publicly; attributes to suspected North Korean actors; rules out private-key compromise 15
September 25–26, 2026 Bitget Loss revised to ~$387.5M as stolen assets traced onto Zcash and TRON 23
September 26, 2026 Bitget Announces phased withdrawal resumption; states User Protection Fund covers the full loss 2
September 28, 2026, 08:00 Bitget Begins phased resumption of withdrawals (BTC on Bitcoin and BSC first) 2

Attack Anatomy

Entry — an undisclosed intrusion into the wallet backend

The initial access vector has not been publicly disclosed. What Bitget has confirmed is the destination: attackers reached "a critical backend system within our wallet infrastructure" — the system that prepares and submits transfer requests, not the key material that signs them (T1078 is a plausible but unconfirmed route; Bitget has not said how the backend was reached).5

Spoofing the transaction data

Rather than forging cryptographic signatures, the attackers manipulated the data flowing through the transfer-preparation system, generating forged transfer requests that the exchange's own approval workflow would accept — runtime manipulation of the authorization pipeline rather than theft of a signing key (T1565.003).5

Draining hot and warm wallets

The forged requests were pushed through the authorization process, which processed them as legitimate and released funds from Bitget's hot and warm wallets across multiple chains — Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base, and later Zcash and TRON — for a total the exchange ultimately put near $387.5 million (T1657). Cold wallets and the self-custodial Bitget Wallet were not affected.125

Loading diagram...

Threat Actor Profile

  • Attacker: Unconfirmed. Bitget attributes the intrusion to suspected North Korean actors at the level of an assessment — "highly consistent with known patterns of North Korean hacker organizations" — based on IP behaviour and on-chain analysis, but no group is named and no government or independent body has publicly confirmed the link.15
  • Attribution confidence: Low to medium, and entirely from the victim. The supporting context — TRM Labs' assessment that DPRK actors account for roughly three-quarters of 2026 crypto theft — describes the year's threat landscape, not this case.4
  • Objective: Direct financial theft. DPRK-linked crypto operations characteristically target exchange infrastructure to fund the state, and prefer methods that abuse trusted internal systems over brute cryptographic attacks — consistent with, though not proof of, what is described here.45
  • Method signature: Compromising the backend that authorizes transfers, rather than stealing keys, echoes the pattern seen in other large 2025–2026 exchange thefts where the weak point was an internal approval or signing workflow rather than the cryptography itself.5

MITRE ATT&CK techniques (verified on attack.mitre.org):

ID Technique
T1657 Financial Theft
T1565.003 Data Manipulation: Runtime Data Manipulation
T1078 Valid Accounts (plausible backend-access route; unconfirmed)

Technical Indicators

incident:
  exchange: "Bitget"
  disclosed_loss_initial_usd: "351.6 million"
  disclosed_loss_revised_usd: "~387.5 million"
  discovery: "2026-09-24 18:31 UTC"
  wallets_affected: "hot and warm"
  wallets_safe: "cold wallets; self-custodial Bitget Wallet"
  chains_touched:
    - Ethereum
    - "XRP Ledger"
    - Arbitrum
    - Avalanche
    - Optimism
    - BSC
    - Base
    - Zcash    # stolen assets later traced here
    - TRON     # stolen assets later traced here
  assets: ["ETH", "XRP", "BNB", "AVAX", "USDT", "USDC"]
  mechanism: "backend wallet-infrastructure compromise -> spoofed transaction data -> forged transfers pushed through authorization workflow; private keys not compromised"
network_iocs: "No attacker wallet addresses or infrastructure IOCs were published in the sources reviewed; the theft was traced on-chain by Mandiant and SlowMist, whose forensic report was pending. Treat exchange-published addresses, when released, as the authoritative IOC set."

No indictment, sanctions action, or government advisory specific to this incident had been published as of this writing; the disclosure and attribution are the exchange's own, with forensic support from Mandiant and SlowMist and unspecified law-enforcement engagement.1 Bitget stated that the loss falls entirely within its User Protection Fund, so the regulatory and customer-restitution exposure is, on the exchange's account, absorbed internally rather than passed to users.2 Whether any national authority formally attributes the theft to a DPRK unit — as has happened with prior large exchange heists — remains open and would be the point at which "suspected" becomes "confirmed."

Impact Assessment

  • Confirmed (per Bitget): A backend compromise of Bitget's wallet infrastructure was used to spoof transaction data and push forged transfers through the exchange's authorization workflow, draining hot and warm wallets across nine chains for a loss the exchange ultimately put near $387.5 million (initially $351.6 million).125
  • Confirmed: Private keys were not compromised; cold wallets and the self-custodial product were unaffected; withdrawals were halted on discovery and resumed in phases from September 28; the User Protection Fund (~$464M) covers the loss.125
  • Assessed: North Korean involvement is suspected on the strength of the victim's IP-behaviour and on-chain analysis, uncorroborated by any government or independent forensic body at the time of writing.14
  • Unknown: The initial-access vector into the backend system; the identity of any specific threat group; the laundering path; and the findings of the pending Mandiant/SlowMist forensics.1

Lessons and Defensive Recommendations

For exchanges and custodians:

  • The signing key is not the only thing worth protecting. This theft treated the transaction-preparation and authorization pipeline as the target, feeding forged-but-well-formed requests into a workflow that trusted its own inputs. Authorization systems should independently validate that a transfer request originated from a legitimate, authenticated source and matches expected patterns (amount, destination, velocity) — not merely that it is well-formed. Out-of-band or multi-party confirmation for large hot/warm-wallet movements raises the bar past "compromise one backend."
  • Segment and monitor the backend that constructs transfers as tightly as the key store. An attacker who can inject into the transfer-preparation system does not need the keys; the two must be defended as one blast radius.

For the wider ecosystem:

  • A funded protection reserve is what turned a $387.5M theft into a contained incident for users. Exchanges that hold customer assets should be able to answer, before an incident, whether a loss of this scale is covered and how — the presence of Bitget's User Protection Fund is why customer balances were reported untouched.
  • Treat single-source attribution with proportion. "Highly consistent with North Korean patterns" from the victim is a reasonable working hypothesis given DPRK's documented dominance of 2026 crypto theft, but it is not the same as a forensic or government attribution, and readers should hold the DPRK label as suspected until an independent body confirms it.

For readers:

  • The headline number moved. The $351.6M figure that circulated first was an early count; the fuller figure is ~$387.5M. When an exchange discloses a loss in the first hours, expect the number to change as on-chain tracing catches assets on additional chains — the first figure is a floor, not a final.

Sources

Footnotes

  1. Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise — The Hacker News, September 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17

  2. Bitget starts phased withdrawal resumption following $388 million exploit — The Block, September 28, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13

  3. Hackers steal $351.6 million in Bitget crypto exchange hack — BleepingComputer, September 2026 ↩ ↩2 ↩3

  4. North Korean hackers suspected in $351M crypto theft, the largest so far this year — TechCrunch, September 25, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8

  5. Bitget's $351 million hack happened via spoofed transfers, not private keys, CEO Gracy Chen says — CoinDesk, September 25, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15

Topics: #bitget#crypto-exchange-hack#dprk#north-korea#spoofed-transfers#wallet-infrastructure#gracy-chen#trm-labs
Original Incident Report →

Related Research

Nobody was hacked. A Chinese CDN company bought the polyfill.io domain, and every site that had ever pasted the script tag started serving whatever the new owner wanted. Four months later it was redirecting phones to betting scams.

Financial FraudSupply Chain Attack

Microsoft's Digital Crimes Unit seized 50 sites and 150+ domains behind EvilTokens, a cybercrime-as-a-service platform pairing device-code phishing with an AI chatbot for inbox analysis and BEC targeting. It hit 12,000+ inboxes across 10,000+ orgs. The AI did the targeting, not the intrusion.

Social EngineeringAI & Machine LearningFinancial Fraud

Rapid7 found 'ted', a backdoor a DPRK-linked APT compiled into victims' HAProxy load balancers as a native plugin — reading their decrypted traffic and routing C2 through the load balancer itself. A companion CurlRAT toolkit hid in five trojanized Linux daemons; targets were South Korean firms.

State-SponsoredMalware