Startupfortune Bitget Hack Attributed to North Korean Actors: $387 Million Stolen
Article Content
- •Bitget lost approximately $387 million due to a hack attributed to North Korean actors.
- •The attack involved unauthorized transfers from hot and warm wallets, executed within three hours.
- •Chainalysis utilized AI to trace the stolen funds across multiple blockchains rapidly.
On September 24, 2026, the crypto exchange Bitget experienced a significant hack, resulting in the theft of approximately $387 million in various cryptocurrencies. The attack was attributed to North Korean-linked actors by Chainalysis, which noted that the stolen funds were transferred across 23 transactions within three hours. Initially estimated at $351.6 million, the total loss increased as more stolen assets were identified. The breach involved unauthorized transfers from Bitget's hot and warm wallets, with the attackers using techniques consistent with previous DPRK hacking incidents. Chainalysis developed AI tools to trace the stolen funds across multiple blockchains, significantly reducing the time needed for tracking from over 20 hours to under 10 minutes. This incident marks a continuation of North Korea's aggressive cyber theft strategy, which has reportedly exceeded $1 billion in crypto thefts for 2026 alone.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Bitget in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What cryptocurrencies were affected?
How quickly did the attackers move the funds?
What measures should Bitget users take?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…