Bitget says attackers transferred approximately $387.5 million from some of its exchange wallets on September 24, 2026. The exchange’s account points to a compromised wallet backend and fraudulent withdrawal instructions, rather than stolen private keys. Investigators have reported possible North Korean links and alleged laundering intermediaries, but those attributions are not confirmed identities.
18
21
30
How the Bitget breach reportedly worked
Bitget detected unauthorized transfers from some hot and warm wallets at about 18:31 UTC. Its preliminary explanation is that an attacker may have exploited a vulnerability in a third-party security product to obtain high-level internal credentials, then used them to send fraudulent withdrawal commands through the wallet system.
21
CEO Gracy Chen said the attacker spoofed transaction data to trigger Bitget’s authorization process. She also described small test transfers before larger transfers; that detail comes from her account of the incident, while the precise method of intrusion remains under investigation. Bitget said private keys were not compromised.
17
29
The reported loss figure was revised from an initial estimate of $351.6 million to $387.5 million after further on-chain tracing included additional assets. Bitget said the revised amount was a more complete accounting of the incident, not a second theft.
30
What is known about the suspected attackers?
Bitget’s CEO said the attack showed hallmarks associated with North Korean operations. Elliptic assessed a North Korean link as highly likely, citing similarities to previous activity and infrastructure overlap, but the available reporting does not establish who carried out the attack.
1
5
A separate part of the investigation concerns people allegedly helping move the proceeds. On-chain investigator ZachXBT said five accounts were involved in laundering funds on behalf of the alleged attackers. He reported that people using services involved in the transfers sought order support in public Discord servers and Telegram channels. These claims are investigator allegations, not a public identification of the people behind the original breach.
10
38
Reports based on ZachXBT’s tracing describe funds moving across chains through bridges and into mixing services, including Wasabi. Such movements can complicate tracing, but they do not by themselves prove who ordered the theft or establish an individual’s identity.
14
36
The reported Kelp DAO overlap
ZachXBT said one account involved in the alleged Bitget laundering activity had also been seen handling funds from the earlier $292 million Kelp DAO exploit. That is a reported overlap involving an account in the movement of funds—not evidence that the same people carried out both hacks.
10
38
Bitget’s investigation, customer coverage and withdrawals
Bitget said it engaged Mandiant and SlowMist to investigate and was working with law enforcement to trace the stolen assets. The exchange also said its User Protection Fund would cover the loss rather than customer balances; Chen said the fund would be replenished to at least $300 million within a week. These are Bitget’s stated plans and assurances, not confirmation that stolen assets have been recovered.
1
17
Withdrawals were initially suspended after the breach. Reports on September 28 said Bitget had begun restoring them in phases. The available reporting does not establish how much of the stolen funds, if any, has been recovered.
7
31
What remains uncertain
The reported transfer amount and the exchange’s account of a wallet-backend compromise are clearer than the questions of attribution and recovery. North Korean involvement remains an assessment, and claims about intermediaries and the Kelp DAO overlap come from blockchain-investigation reporting. The full intrusion method and the final recovery outcome remain unresolved in the available information.
5
21
38