Skip to content
North Korean Hackers Strike Bitget for $351M in Crypto

North Korean Hackers Strike Bitget for $351M in Crypto

Techbuzz.Ai • September 25, 2026

Bitget exchange loses $351M to suspected North Korean hackers in 2026's biggest theft

PUBLISHED: Fri, Sep 25, 2026, 2:05 PM UTC | UPDATED: Fri, Sep 25, 2026, 2:05 PM UTC

Cryptocurrency exchange Bitget just suffered a devastating $351 million hack, marking the largest crypto theft of 2026 so far. Security researchers are pointing fingers at North Korean state- groups, adding another massive score to Pyongyang's growing crypto war chest. The breach highlights the persistent vulnerability of centralized exchanges despite years of security improvements across the industry.

The crypto world woke up to devastating news as Bitget , one of the world's largest cryptocurrency exchanges, confirmed a $351 million theft that security researchers are attributing to North Korean hackers. The massive breach represents the single largest crypto theft of 2026, surpassing incidents and highlighting the persistent threat posed by state- cybercriminals.

The attack bears the hallmarks of North Korea's notorious Lazarus Group, according to preliminary analysis from blockchain security firms. These state-backed hackers have systematically targeted crypto exchanges and DeFi protocols, stealing an estimated $3 billion since 2017 to fund the country's weapons programs and circumvent international sanctions.

Bitget's security team detected the breach early Friday morning when unusual withdrawal patterns triggered automated alerts. By then, the attackers had already moved substantial amounts of Bitcoin, Ethereum, and other digital assets through a sophisticated network of mixer services designed to obscure the funds' trail. The exchange immediately halted all withdrawals and launched an investigation with help from Chainalysis and other blockchain forensics specialists.

"We're working around the clock with law enforcement and security partners to track these funds," a Bitget spokesperson said in a statement. "Our users' safety remains our top priority, and we're implementing additional security measures to prevent future incidents."

The timing couldn't be worse for the crypto industry, which has been fighting to rebuild trust after a series of high-profile collapses and security breaches. Major exchanges like Binance and Coinbase have invested hundreds of millions in security infrastructure, yet centralized platforms continue to present attractive targets for sophisticated attackers.

North Korean hackers have become increasingly brazen in their crypto operations, with U.S. officials estimating they've stolen over $1 billion in digital assets just this year. The funds typically flow through complex laundering schemes involving privacy coins, decentralized exchanges, and mixing services before eventually reaching North Korean state coffers.

The Bitget incident follows a pattern established in North Korean attacks on exchanges like Ronin Network and Harmony Protocol. Attackers typically exploit vulnerabilities in cross-chain bridges or compromise private keys through sophisticated social engineering campaigns targeting exchange employees.

Blockchain analysis reveals the stolen funds were immediately split across multiple wallets and began moving through Tornado Cash and other mixing protocols within hours of the theft. This rapid laundering attempt suggests the attackers had pre-planned their exit strategy, a trademark of professional state- operations.

The breach has already sent ripples through crypto markets, with Bitcoin dropping 3% in early trading as investors worry the security implications. Bitget's native token BGB plummeted nearly 15% before the exchange announced it would cover all user losses from its insurance fund.

Regulators in multiple jurisdictions are now scrutinizing the incident, with the U.S. Treasury Department's Office of Foreign Assets Control expected to add new wallet addresses to its sanctions list. South Korean authorities, who have been particularly aggressive in tracking North Korean crypto activities, announced they're coordinating with international partners on the investigation.

For Bitget, which handles over $10 billion in daily trading volume, the hack represents both a massive financial blow and a serious reputational crisis. The exchange has promised full compensation for affected users but faces an uphill battle to restore confidence in its security practices.

This $351 million theft underscores the ongoing cat-and-mouse game between crypto exchanges and state- hackers. While the industry has made significant security improvements, centralized platforms remain vulnerable to sophisticated attacks, particularly from well-funded adversaries like North Korea's cyber units. The incident will likely accelerate calls for stricter security standards and may influence pending crypto regulations worldwide. For now, all eyes are on whether authorities can successfully track and recover the stolen funds - a challenge that has proven nearly impossible in North Korean crypto heists.

Extracted Entities

APT Groups (1)

Attack Types (1)

Countries (1)

Industries (1)

MITRE ATT&CK (1)