Cnbc Bitget Suffers $388 Million Hack Linked to North Korean Hackers
Article Content
- •Bitget lost approximately $388 million in a cyberattack linked to North Korean hackers.
- •The exchange has frozen $1.1 million of the stolen funds and replenished its protection fund.
- •The attack exploited vulnerabilities in third-party security products, allowing unauthorized access.
Bitget, a cryptocurrency exchange, reported a cyberattack resulting in the theft of approximately $388 million. The attack is suspected to be linked to North Korean hackers, as indicated by CEO Gracy Chen. The breach involved unauthorized transfers from the exchange's hot wallets, which are used for active trading. Following the incident, Bitget froze around $1.1 million of the stolen funds and replenished its user protection fund to over $300 million using its own reserves. Chen noted that the recovery of stolen assets is expected to be limited, citing the challenges faced by exchanges in recovering funds after such hacks. The attack exploited vulnerabilities in two third-party security products, allowing attackers to gain privileged access without stealing private keys. Bitget has suspended crypto withdrawals while it investigates the breach. The incident marks the largest known crypto theft of 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Bitget in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What is the estimated loss from the hack?
What measures is Bitget taking post-attack?
Are user accounts affected by the breach?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…