Advertisement

Could AI answer your customers from your own documents?

Assistants trained on your files, website and FAQs.

Hack Database

Bitget: Hackers Took $387.5 Million by Faking the Exchange's Own Paperwork

Suspected North Korean hackers took $387.5 million from Bitget by feeding its own security system fake paperwork. No password or key was stolen.

Bitget: Hackers Took $387.5 Million by Faking the Exchange's Own PaperworkPhoto: Bitget. Logo: Bitget, via Wikimedia Commons
Gracy Chen, Bitget's chief executive.

Key numbers

  • $387.5M

    Stolen

  • 5,500 BTC

    Protection Fund

  • ~$0.3M

    Frozen

  • North Korea (TraderTraitor)

    Suspected attacker

At 18:31 UTC on 24 September 2026, half past seven in the evening in London, Bitget's security systems flagged money leaving the company that nobody at the company had asked to send. Bitget is a crypto exchange, a business that works like an online stockbroker: it holds its customers' digital money and lets them buy and sell. Over the next three hours its own systems paid out hundreds of millions of dollars to strangers, and approved every payment as it went.

The final count was $387.5 million. Bitget first put the figure at $351.6 million, then raised it the next day after finding missed transfers on two more networks, Zcash and TRON. That makes it the largest crypto theft of 2026 so far, ahead of the $319 million taken from Liquid Network earlier in September and the April attacks on Kelp DAO ($292 million) and Drift Protocol ($285 million).

Bitget was founded in Singapore in 2018, is registered in the Seychelles and says it serves more than 120 million users. Its chief executive, Gracy Chen, confirmed the breach on X at about 21:30 UTC, three hours after it began. Outsiders had already noticed. Emmett Gallic, an analyst at the blockchain tracking firm Arkham Intelligence, posted at 20:24 UTC that Bitget appeared to have been hacked for about $178 million.

Bar chart of the largest crypto thefts of 2026: Bitget $387.5M, Liquid Network $319M, Kelp DAO $292M, Drift Protocol $285MCMZ chart. Data: Bitget, TRM Labs
The largest crypto thefts of 2026.
Advertisement

Free AI assistant

AI that works, and proves it.

Ask Cynt how AI could help your business. Free to try.

Free AI assistant

How it worked

Exchanges keep customer money in layers. Most of it sits in "cold" storage, held offline like gold in a vault. A smaller amount sits in "hot" wallets connected to the internet, the equivalent of the cash drawer at a bank counter, so customers can withdraw quickly. Bitget also runs a middle "warm" layer that refills the drawer. Money leaves any of them only when the exchange's authorisation system approves a transfer and signs it with a private key, the digital version of a bank manager countersigning a cheque.

Nobody stole a password, and the attackers never touched the keys. According to Chen, they compromised "a critical backend system within our wallet infrastructure", used it to spoof transaction data, and let Bitget's own authorisation process do the rest. In banking terms, a thief inside the accounts department slipped forged payment instructions into the day's batch. The manager's countersignature on each one was genuine. The instructions were not. "Private key compromise has been ruled out," Chen said. The cold vault was untouched. Bitget has not said publicly how the attackers got into that back-office system in the first place.

The payouts came in bursts. Bitquery, a blockchain data company that rebuilt the sequence, counted 21 transfers across eight blockchains, which are separate payment networks with their own coins, much as different stock exchanges settle their own trades. Two bursts, at 19:01 and 19:16 UTC, each took no more than 15 seconds. The last transfer went at 21:23 UTC. The haul included about 103 million XRP worth roughly $157 million, the largest single piece, plus ether, BNB, AVAX, TRX and Zcash, the stablecoins USDT and USDC (digital dollars issued by Tether and Circle), and even XAUt, a Tether token backed by gold.

Bar chart of assets taken from Bitget by blockchain network, led by $157.8M on the XRP Ledger and $126.6M on EthereumCMZ chart. Data: Bitquery
What left Bitget, network by network.

The trick was not new. In February 2025 the exchange Bybit lost about $1.5 billion when the staff approving a routine transfer saw one thing on their screens while the blockchain received another. The software showing them the details, supplied by an outside firm called Safe{Wallet}, had been tampered with, and the FBI blamed North Korea. Both times the signatures were real and the paperwork was fake.

Who did it

Chen said North Korean involvement was "very likely". Investigators, she said, had found internet addresses matching the VPN services, tools that disguise where a computer really is, previously favoured by a North Korean hacking group. Bitget has brought in Mandiant, the incident-response arm of Google, and the security firm SlowMist, and has informed law enforcement.

The blockchain analysts went further. TRM Labs found that the wallets laundering the money overlapped with those used after the Bybit theft and after the July 2026 raid on AFX Trade's bridge, and said it had never linked that laundering network to anyone else. Its conclusion was that the overlaps point to TraderTraitor, the name the FBI gave the North Korean operation behind Bybit, part of the wider Lazarus Group. Elliptic counts Bitget as the largest theft attributed to North Korea this year and says it pushes the country's suspected crypto haul for 2026 past $1 billion. No government has formally attributed the attack, and nobody has been charged.

Chen says she has met these people before. About eighteen months earlier she lost roughly $80,000 from a personal wallet after attackers posing as journalists from a crypto news outlet approached her for an interview, and she has linked that incident to the same North Korean group. There is a further irony. When Bybit was robbed in 2025, Bitget lent it 40,000 ether, then worth more than $100 million, with no interest and no collateral, so Bybit could keep paying its customers. Bybit repaid the loan within days.

Where the money went

The attackers moved first on anything that could be frozen. Stablecoins such as USDT and USDC have an off switch: Tether and Circle can blacklist an address, much as a bank can freeze an account. Elliptic found the stolen stablecoins were quickly swapped into each network's own coin. The issuers still froze about $0.3 million, less than a tenth of one per cent of the total. XRP has no such switch, not even for Ripple, the company most closely tied to it, and by 26 September about $83 million of the stolen XRP had been moved on, according to CoinDesk.

Much of the rest sat still. On 26 September, 68,295 ether worth about $184 million rested in eight untouched wallets, according to Bitquery. Smaller sums went through THORChain and Chainflip, services that swap one coin for another across networks without asking who is swapping, and came out as bitcoin: about 127 bitcoin, roughly $10.6 million, by the afternoon of 25 September. On 27 September the tracing firm AMLBot followed about 4 bitcoin into Wasabi Wallet's CoinJoin, a mixer that pools many people's coins so that individual payments can no longer be told apart.

THORChain became the argument. On 26 September Chen publicly asked it to refuse service to the attackers' addresses, arguing that decentralisation should not be a shield for moving known stolen money. THORChain declined, replying on X that it is decentralised and permissionless, like Bitcoin, Ethereum and BNB Chain. Star Xu, founder of the rival exchange OKX, answered that a network able to halt itself when its own funds are at risk, but unwilling to do so for anyone else's, is not like Bitcoin. The row is a rerun. After the Bybit theft, roughly $1.2 billion of the stolen money passed through THORChain.

What happened next

Bitget says no customer will lose money. It is paying for the loss from its User Protection Fund, a reserve set aside for exactly this kind of event, and has promised to refill it. The fund holds 5,500 bitcoin, worth about $464 million when the theft was announced. Because it is held in bitcoin rather than dollars, the cover moves with the market: 5,500 bitcoin pays for $387.5 million only while bitcoin stays above roughly $70,500. On the morning of 28 September bitcoin traded near $83,000, according to CoinGecko.

Customers could trade and deposit throughout, but they could not take anything out, the position of a broker's client who can buy and sell shares but cannot withdraw cash. Bitget's reopening plan starts with bitcoin at 08:00 UTC on 28 September, then ether on 29 September, USDT on 30 September and everything else, including withdrawals in ordinary money, on 2 October. At 06:00 UTC on 28 September, two hours before the start, Bitget's public data still showed withdrawals switched off on every network.

Bitget has also put a price on getting the money back: 5% of any funds frozen and another 5% of any funds recovered, paid to whoever makes it happen, with Bybit's LazarusBounty site as one of the channels. Changpeng Zhao, founder of Binance, offered help without saying what kind. Bitget's own BGB token, whose price tends to track confidence in the exchange, fell a few per cent the next day. Chen, meanwhile, repeated that Bitget still plans to list its shares on a stock market within three years.

The aftermath

As of 28 September 2026, Bitget says the flaw has been found and fixed, no further unauthorised transfers are possible, and every customer balance is intact. The $387.5 million loss is being covered from the 5,500-bitcoin User Protection Fund, which Bitget has promised to refill; the cover holds while bitcoin stays above about $70,500. Withdrawals, frozen from 24 September, began reopening in stages from 28 September. Customers then pulled out a net $463 million in the 24 hours to 29 September, the largest one-day outflow DefiLlama has recorded in four years of tracking exchange reserves, leaving Bitget with about $5.7 billion.

Very little of the money has come back. Tether and Circle froze roughly $320,000 to $340,000 in stablecoins. About $83 million of XRP, which cannot be frozen, had been moved on by 26 September, some $10.6 million had been swapped into bitcoin through THORChain and Chainflip, and about 4 bitcoin had entered a Wasabi CoinJoin mixer. Around 68,000 ether sat untouched in the attackers' wallets. Bitget is offering 5% of any funds frozen and 5% of any funds recovered.

Attribution rests on Bitget's own investigation and on blockchain analytics firms: Chen called North Korean involvement very likely, TRM Labs tied the laundering to TraderTraitor, and Elliptic counts it as North Korea's largest theft of 2026. No government has formally attributed the attack and no one has been charged. Mandiant and SlowMist are investigating. On 28 September Bitget's chief executive, Gracy Chen, said how the attackers got in: through a "zero-day", a flaw nobody had yet found, in a security product made by an outside company that Bitget used. That gave them high-level staff passwords, and from there they sent withdrawal orders that the wallet system treated as routine. They first sent two small test transfers below Bitget's alarm limit; the large ones followed about 30 minutes later.

From 30 September, according to the investigator ZachXBT, the thieves began moving the stolen ZEC coins into Ironwood, Zcash's private pool, which hides who sent what to whom. About 2,700 ZEC, roughly $3.8 million, went in first, out of about 18,900 ZEC taken. Once money is inside such a pool, nobody can follow it.

What this teaches

  • A genuine signature proves nothing if the system that prepares the paperwork is compromised. Bybit in 2025 and Bitget in 2026 both approved transfers that looked routine because the data put in front of the approver had been faked.
  • Keeping most money in offline cold storage limited the damage. The attackers emptied parts of the hot and warm layers, not the vault.
  • Freezable assets get dumped first. Stablecoin issuers froze only about $0.3 million because the attackers swapped out of USDT and USDC within hours, and native coins such as XRP and ether cannot be frozen by anyone.
  • A protection fund held in bitcoin is only worth what bitcoin is worth. Bitget's 5,500 BTC covers a $387.5 million loss only above about $70,500 a coin.
  • Swap services that will not block known stolen funds remain the main exit for North Korean hauls, as THORChain showed after Bybit and again after Bitget.
Advertisement

Powered by Cyntri AI

The technology behind this newsroom. Built by Cyntri AI.

AI-assisted publishing, content pipelines and analytics. Crypto Media Zone is our working example.

Powered by Cyntri AI