Suspected DPRK Hackers Steal $351.6M from Bitget
Bitget says suspected North Korean actors stole $351.6 million from hot and warm wallets in a backend compromise detected at 18:31 UTC on September 24.

Bitget confirmed September 25 that $351.6 million was stolen from its hot and warm wallets. The exchange attributed the theft to suspected North Korean threat actors. Compromise detected: 18:31 UTC, September 24, 2026.
Attribution is described as “suspected” in Bitget’s own statement and in reporting by BleepingComputer and The Hacker News. Confidence on DPRK attribution: unconfirmed. No specific threat group has been publicly named.
Known scope
Hot wallets are internet-connected, used to fund active trading. Warm wallets have partial connectivity. Bitget has not disclosed cold storage impact in initial reporting.
Time from detection to public statement: under 16 hours. Investigation is ongoing. No recovery or asset freeze details have been disclosed.
Context
North Korean state actors have a documented pattern of large-scale crypto theft. Separately, WaterPlum targeted job seekers across roughly 30,000 devices earlier this month, and Jade Sleet deployed custom backdoors against an Indian IT provider the same week. Analysis: if DPRK attribution for the Bitget compromise holds, the incident fits the revenue-generation model documented across prior DPRK exchange and DeFi operations by blockchain analytics firms and U.S. law enforcement. Attribution is subject to revision as investigation continues.
Found this useful? Share it.


