Bitget Loses USD 351.6 Million in Hot Wallet Breach in Likely North Korea Attack

TRM Team

TRM User Conference

Which mission will you select?

REGISTER NOW
November 2-3, 2026
Washington, D.C.
Bitget Loses USD 351.6 Million in Hot Wallet Breach in Likely North Korea Attack

On September 24, 2026, attackers moved an estimated USD 351.6 million out of Bitget’s hot and warm wallets across Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain, and Base. Bitget detected the unauthorized transfers at 18:31 UTC, paused withdrawals, and said the loss falls within its User Protection Fund. It is the largest crypto theft of 2026 by value so far.

Key takeaways

  • Attackers moved an estimated USD 351.6 million from Bitget’s hot and warm wallets on September 24, 2026. Bitget says they compromised a backend system, manipulated the transaction data shown to its authorization process, and caused it to approve the transfers. The exchange says its private keys were not stolen.
  • Early estimates of USD 170–190 million covered the EVM chains. TRM data shows about USD 158 million also left through the XRP Ledger, bringing the observed outflows close to Bitget’s reported loss.
  • The stolen ETH and XRP were quickly split among new wallets, many holding round amounts of roughly 10,000 ETH or 20 million XRP. By the morning of September 25, most of those funds had not moved again.
  • Bitget paused withdrawals and says its USD 464 million User Protection Fund covers the loss. It says cold wallets were unaffected.
  • Bitget’s CEO has described North Korean involvement as “very likely,” though TRM has not definitively attributed the attack. Multiple on-chain links to previously identified North Korean thefts, including Bybit and AFX Bridge, point toward North Korean involvement. Those links run through a laundering network TRM has not observed working with any other group, though another actor carrying out the theft remains technically possible.

{{horizontal-line}}

How the attack worked

Exchanges use hot and warm wallets to process withdrawals while keeping most customer assets in cold storage. Transfers from those wallets still require approval before they are signed. Bitget CEO Gracy Chen said an attacker gained access to a backend system connected to its wallet infrastructure, spoofed transaction data, and triggered that approval process. Bitget says its private keys were not compromised and its cold wallets were unaffected.

The failure resembles the February 2025 Bybit theft in one respect: the attacker manipulated what the people or systems authorizing a transfer saw. At Bybit, that led signers to approve a transfer from a cold wallet. At Bitget, according to the exchange, it caused its withdrawal controls to authorize transfers from hot and warm wallets. Neither account depends on stolen private keys.

Early onchain estimates put the loss at USD 170–190 million because they covered Ethereum and other EVM chains. Bitget reported a loss of USD 351.6 million. TRM data shows approximately USD 158 million in XRP and USD 7 million in TRX also leaving Bitget wallets, bringing the observed outflows close to the exchange’s figure.

The proceeds were split into round-number wallets within hours

On Ethereum, much of the stolen value passed through 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee, which also received funds on Arbitrum, Avalanche, Base, BNB Chain, and Optimism. A second wallet, 0xa6dd3f218b65e32ccc37be30f74884133c655545, distributed its balance to newly created wallets over roughly two hours on the evening of September 24. Most received about 10,000 ETH each. Together with wallets funded directly from the first address, eight wallets received most of the stolen ETH. None had sent funds onward as of the morning of September 25.

The XRP followed a similar pattern. Funds leaving Bitget passed through smaller relay accounts before arriving in separate accounts holding round amounts of 20 million XRP. Most of that XRP also remained in place as of the morning of September 25.

Some of the proceeds had begun moving toward Bitcoin. Funds on BNB Chain and Ethereum were swapped through THORChain and split across Bitcoin addresses in peel chains. On TRON, stolen TRX was swapped for USDT on SunSwap, moved to Ethereum through USDT0, and entered the same THORChain route. Smaller amounts passed through Across, Bridgers, Chainflip, and FixedFloat.

TRM Forensics has attributed and tagged exploiter addresses under “Bitget Exploiter September 2026.” The tags have expanded from Ethereum to other chains, including the XRP Ledger and Bitcoin, and cover intermediary wallets farther along the fund flow.

The flow below shows one path from a Bitget hot wallet on BNB Chain to THORChain. About USD 9.8 million in BNB left Bitget on the evening of September 24 and passed through several exploiter wallets before being divided into smaller amounts. Over the next roughly 13 hours, portions reached THORChain in transfers of a few hundred thousand USD each and were converted to Bitcoin.

Figure 1: One path of Bitget exploit proceeds on BNB Chain, from a Bitget hot wallet through exploiter and hop wallets to THORChain.

What the North Korea claim rests on

Bitget CEO Gracy Chen has said North Korean involvement is “very likely,” citing IP addresses that Bitget’s preliminary investigation linked to VPN services associated with a North Korean hacking group. As in the February 2025 Bybit theft, which the FBI attributed to North Korea, the attacker manipulated the information used to approve a transfer rather than stealing private keys.

Onchain tracing of the hack proceeds has revealed multiple overlaps with wallets used to launder previous North Korean hacks, including Bybit and AFX Bridge. At a minimum, these onchain links confirm the group laundering these proceeds is the same one used by TraderTraitor in other recent hacks. TRM has not linked this laundering syndicate to any other hacking group’s thefts; these overlaps therefore point to TraderTraitor. TRM expects harder technical evidence for this linkage to emerge in the coming days.

The laundering of the Bitget proceeds is typical of recent North Korean heists. Within hours, the funds were split into fresh wallets holding round amounts, most of which then sat still. The share that has moved has gone through swap services, including THORChain, into ETH and BTC. Those services and techniques are also available to other actors.

If the Bitget theft is attributed to North Korea, 2026 would become the second-largest year on record for North Korean crypto theft in TRM’s data, with more than USD 1 billion stolen, behind only 2025. Hacks attributed to North Korea account for about USD 690 million in 2026 so far, most of it from the Drift Protocol and KelpDAO attacks.

Figure 2: Value stolen in hacks attributed to North Korea with high or medium confidence in TRM’s hack dataset, 2017–2026. 2026 data runs through September 16, with Bitget’s reported USD 351.6 million shown separately; TRM has not attributed the Bitget theft.

What happens next

The funds that have not moved are the largest open question. As of the morning of September 25, most of the stolen ETH and XRP was still in the holding wallets described above. After the Bybit theft, a large portion of the converted bitcoin sat largely stationary before the next stage of laundering through mixers and over-the-counter (OTC) networks, and proceeds from Drift were left dormant in fresh wallets after the attack.

Whenever the Bitget funds do move, the route so far suggests where they are likely to surface. Proceeds that pass through bridges, cross-chain swap services, and Bitcoin peel chains tend to reach exchanges several hops away from a tagged address rather than directly from one, so connecting those deposits to the exploit depends on tracing across hops and chains.

Attribution is the other open question. Bitget’s promised incident report may show how the backend system was compromised and whether the evidence points to North Korea. TRM is monitoring the tagged addresses and will update this post as attribution and fund flows develop. For a broader view of the trends shaping illicit crypto activity, see TRM’s 2026 Crypto Crime Report.

{{horizontal-line}}

Frequently asked questions (FAQs)

1. What happened in the Bitget hack?

On September 24, 2026, attackers moved an estimated USD 351.6 million out of Bitget’s hot and warm wallets across seven blockchains. Bitget detected the transfers at 18:31 UTC, paused withdrawals, and said its User Protection Fund covers the loss. Bitget says its cold wallets were not affected.

2. What is a hot wallet compromise?

A hot wallet is an internet-connected wallet an exchange uses to process everyday withdrawals, while most assets stay in offline cold storage. A hot wallet compromise lets an attacker move funds out of that working balance, either by stealing keys or, as Bitget describes, manipulating the systems that approve transfers so the exchange signs them itself. In the Bitget case, private keys were not taken.

3. How much was stolen from Bitget?

Bitget’s CEO put the loss at about USD 351.6 million. Onchain trackers in the first hours estimated USD 170–190 million, but that covered only the EVM chains. TRM data shows about USD 158 million more left through the XRP Ledger, bringing the total close to Bitget’s figure. This post uses Bitget’s figure.

4. Was North Korea behind the Bitget hack?

Bitget’s CEO has said North Korean involvement is “very likely,” citing IP addresses that matched VPN services associated with a North Korean hacking group. TRM has not yet definitively attributed the exploit to North Korea.

5. Where did the stolen funds go?

The proceeds were consolidated and then split into newly created wallets holding round amounts, including several of about 10,000 ETH each and several of 20 million XRP each. As of the morning of September 25, most of those funds had not moved, and a smaller share had passed through THORChain into Bitcoin. The exploiter addresses are tagged in TRM Forensics as “Bitget Exploiter September 2026.”

6. What should exchanges and virtual asset service providers do now?

Screen incoming deposits against the tagged Bitget exploiter addresses and against funds several hops downstream of them, not only direct transfers. Proceeds are moving through bridges and cross-chain swap services, so deposits are more likely to arrive indirectly. Members of the Beacon Network receive exploiter addresses as they are identified.

This is some text inside of a div block.
Subscribe and stay up to date with our insights
No items found.