Skip to content
Elliptic also assessed

Elliptic also assessed

www.elliptic.co • September 26, 2026

Multiple indicators suggest the over $350 million exploit of Bitget exchange is highly likely to be linked to the Democratic People's Republic of Korea (DPRK).

Yesterday, Bitget - a major global cryptoasset exchange - experienced a security incident in which over $350 million in ‘unauthorized transfers’ were withdrawn from Bitget hot wallets. Following the incident, Bitget CEO Gracy Chen published an update on X , stating "this attack is consistent with techniques used by DPRK-linked hacker groups."

This latest incident takes place amid broader DPRK-linked activity targeting the cryptoasset ecosystem, pushing Elliptic's tracked total of DPRK-attributed cryptoasset theft in 2026 past the $1 billion mark.

How did the Bitget attack unfold? How did the Bitget attack unfold?

Bitget detected unauthorized transfers from its hot and warm wallet infrastructure at approximately 18:31 UTC on 24 September, 2026, impacting a variety of cryptoassets including ETH, XRP, BNB, AVAX, USDT, USDC, across the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base networks. Cold storage was reported unaffected and the exchange suspended withdrawals as a precaution.

Chen said the incident did not involve a private key compromise. Instead, she described attackers compromising a backend system within Bitget's wallet infrastructure, using it to spoof transaction data. Bitget has said its User Protection Fund fully covers the loss.

Elliptic identified and labeled addresses associated with the exploit shortly after the first alerts.

Why Elliptic assesses this as highly likely to be DPRK-linked Why Elliptic assesses this as highly likely to be DPRK-linked

The following factors inform Elliptic's assessment:

Infrastructure overlap: As first reported by Specter on X , connections between XRP from the Bitget exploit and ETH from a DPRK-attributed exploit have been observed. Elliptic observed further connections between stolen Bitget funds and addresses involved in the laundering of DPRK-attributed exploits, including the exploit of Bybit in 2025. Shared laundering infrastructure between incidents is a recurring feature in the laundering of DPRK-attributed hacks, with launderers prioritizing speed over operational discipline.

Off-chain indicators: As indicated by Chen in a post on X, the off-chain indicators are consistent with indicators observed in DPRK-attributed operations.

Laundering methodology: The stolen funds were converted rapidly out of stablecoins and other non-native tokens into each chain's native asset, a technique consistent with DPRK laundering, as previously documented by Elliptic . The exception to this also points to DPRK: stolen assets on Arbitrum were quickly cross-chained to Ethereum, potentially reflecting lessons learned from the laundering of KelpDAO, in which the Arbitrum Security Council took emergency action to freeze 30,766 ETH.

Bitget's statement: During a livestream on X , Chen stated the perpetrator was "likely a North Korean group," though the exchange's own technical basis for that attribution has not yet been published.

Precedent: The majority of the most significant centralized exchange and bridge hacks in recent years have ultimately been attributed to DPRK-linked actors. The list includes Ronin Bridge (2022), Atomic Wallet (2023), CoinsPaid (2023), Alphapo (2023), Stake.com (2023), CoinEx (2023), WazirX (2024) and Bybit (2025).

Taken together, this incident would be the largest single cryptoasset theft attributed to North Korea in 2026, a year in which Elliptic has already tracked more than 51 DPRK-linked incidents.

How Elliptic is supporting its customers How Elliptic is supporting its customers

We urgently updated our datasets to reflect the addresses linked to this incident. Customers using Elliptic solutions will see the newly designated addresses reflected in their screening, monitoring and investigation workflows.

Elliptic customers can screen against the addresses linked to this incident now. To find out how Elliptic's screening and investigation solutions can help your business detect and respond to state-linked threats like this one, our team today .

Dive deeper Dive deeper

Bybit exploit 12 months on: the DPRK threat continues Bybit exploit 12 months on: the DPRK threat continues

Drift Protocol exploited for $286 million in suspected DPRK-linked attack Drift Protocol exploited for $286 million in suspected DPRK-linked attack

OFAC sanctions a fraud network for assisting the North Korean (DPRK) regime OFAC sanctions a fraud network for assisting the North Korean (DPRK) regime

Market structure stays with the SEC and CFTC. You remain accountable for your agents Market structure stays with the SEC and CFTC. You remain accountable for your agents

Extracted Entities

Attack Types (1)

Countries (1)

Domains (1)