Bankinfosecurity Bitget Suffers $388M Hack Attributed to North Korean Lazarus Group
Article Content
- •Bitget lost approximately $388 million due to a hack attributed to North Korea's Lazarus Group.
- •The attackers exploited a vulnerability in third-party software to forge withdrawal commands.
- •Bitget's protection fund covered all customer losses, and withdrawals have resumed in phases.
On September 24, 2026, Bitget reported a significant security breach resulting in the theft of approximately $388 million from its hot and warm wallets. The attackers exploited a vulnerability in a third-party security product to gain internal access credentials and issued fraudulent withdrawal commands. Bitget's cold wallets remained secure, and private keys were not compromised. The incident has been linked to North Korea's Lazarus Group, known for previous cyberattacks. Following the breach, Bitget temporarily suspended withdrawals and has since resumed them in phases, with a protection fund covering customer losses. Investigations by security firms Mandiant and SlowMist are ongoing, focusing on the attack's methods and tracing the stolen funds, which have begun moving through various mixers and exchanges. As of October 1, 2026, some funds remain unspent, providing a target for ongoing investigations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (11)
Following this threat?
Track Lazarus Group and Bitget in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What specific vulnerabilities were exploited?
How much of the stolen funds have been traced?
What measures is Bitget taking to prevent future attacks?
Continue Reading
Bybit and Bitget Collaborate After $1.4 Billion Hack Linked to Lazarus Group On February 21, 2026, Bybit suffered a $1.4 billion hack attributed to North Korea's Lazarus Group. In response, Bybit borrowed 40,000 ETH from Bitget to facilitate customer withdrawals and repaid the loan within three days. The attack resulted in significant withdrawals, with over $5 billion taken out by investors…