Skip to content
Bitget Suffers $388M Hack Attributed to North Korean Lazarus Group

Bitget Suffers $388M Hack Attributed to North Korean Lazarus Group

First seen 4 Oct 2026, 11:01 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 12:01 UTC
  • •Bitget lost approximately $388 million due to a hack attributed to North Korea's Lazarus Group.
  • •The attackers exploited a vulnerability in third-party software to forge withdrawal commands.
  • •Bitget's protection fund covered all customer losses, and withdrawals have resumed in phases.

On September 24, 2026, Bitget reported a significant security breach resulting in the theft of approximately $388 million from its hot and warm wallets. The attackers exploited a vulnerability in a third-party security product to gain internal access credentials and issued fraudulent withdrawal commands. Bitget's cold wallets remained secure, and private keys were not compromised. The incident has been linked to North Korea's Lazarus Group, known for previous cyberattacks. Following the breach, Bitget temporarily suspended withdrawals and has since resumed them in phases, with a protection fund covering customer losses. Investigations by security firms Mandiant and SlowMist are ongoing, focusing on the attack's methods and tracing the stolen funds, which have begun moving through various mixers and exchanges. As of October 1, 2026, some funds remain unspent, providing a target for ongoing investigations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-24
Bitget Hack Disclosed
Bitget announced unauthorized transfers totaling approximately $388 million from its wallets, attributed to a third-party software vulnerability.
Coingeek
2026-09-28
Withdrawals for Bitcoin Resumed
Bitget began resuming withdrawals for Bitcoin following the hack, as part of its recovery efforts.
Finance.Yahoo
2026-10-01
Investigation Update Released
Blockchain intelligence firm BitOK traced approximately 87.82 BTC from the stolen funds, which remained unspent at that time.
Bravenewcoin
2026-10-02
Withdrawals for Other Assets Resumed
Bitget resumed withdrawals for Ethereum and other cryptocurrencies as part of its recovery plan.
Finance.Yahoo
2026-10-04
Investigation Findings Confirmed
Mandiant and SlowMist confirmed the attack's method, linking it to vulnerabilities in third-party security products.
Bitget

More articles in this cluster (11)

Following this threat?

Track Lazarus Group and Bitget in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What specific vulnerabilities were exploited?
The attackers exploited a vulnerability in a third-party security product to gain internal access credentials.
How much of the stolen funds have been traced?
As of October 1, approximately 87.82 BTC from the stolen funds has been traced and remains unspent.
What measures is Bitget taking to prevent future attacks?
Bitget is conducting investigations with Mandiant and SlowMist and has resumed withdrawals while ensuring its protection fund covers customer losses.