Home / Crime and Justice / North Korea Linked to $387M Crypto Heist

North Korea Linked to $387M Crypto Heist

Summary

  • Crypto exchange Bitget lost $387.5 million in a suspected North Korean hack.
  • Attackers exploited a backend system, spoofing transaction data for access.
  • Bitget's User Protection Fund covers the loss, with withdrawals still paused.
North Korea Linked to $387M Crypto Heist

Crypto exchange Bitget reported an estimated $387.5 million stolen in a sophisticated cyberattack, with investigators citing North Korea as the likely culprit. The breach on Thursday, September 25, 2026, involved unauthorized transfers from Bitget's hot wallets. Security analysts noted the attack compromised a backend system, allowing the spoofing of transaction data to trick the exchange's authorization processes. Cold wallets remained unaffected, and Bitget Wallet users were not impacted.

Bitget CEO Gracy Chen indicated that IP addresses and attack patterns align with previous activities attributed to North Korean hacking groups. Blockchain analytics firms Elliptic and TRM Labs also assess a high likelihood of North Korean state-sponsored actors, such as the Lazarus Group, being responsible. This incident is considered the largest suspected North Korean crypto theft of 2026, with cumulative regime gains since 2017 exceeding $6 billion.

While withdrawals from Bitget are temporarily suspended pending a security review, deposits and trading remain active. The exchange expects to announce a withdrawal plan by September 26, 2026, at 4:00 AM UTC. Bitget stated that its User Protection Fund, valued at over $464 million, will cover the full loss. Authorities and blockchain foundations have taken steps to freeze some attacker-linked wallets holding smaller amounts.

Disclaimer: This story has been auto-aggregated and auto-summarised by a computer program. This story has not been edited or created by the Feedzop team.

Read more news on

Property Code: 5571