Bitget Reports $351.6 Million Theft Following Backend Compromise
Suspected North Korean actors identified; exchange hot and warm wallets targeted

Key Takeaways
- Bitget reported a $351.6 million theft from hot and warm wallets on September 24, 2026.
- Suspected North Korean threat actors are attributed as the perpetrators by the exchange.
- Cold wallets and the majority of platform assets were stated to remain secure.
- The specific backend compromise vector and independent verification of actor attribution are pending.
- No patch is available; the exchange is likely implementing enhanced security controls and wallet segregation.
Quick answers
- What happened?
- Cryptocurrency exchange Bitget disclosed that suspected North Korean threat actors stole approximately $351.6 million from its hot and warm wallets following a backend compromise detected on September 24, 2026. The company's cold wallets and the majority of platform assets were reported to remain secure.
- Which products are affected?
- Bitget hot wallets, Bitget warm wallets
- What should defenders do?
- Bitget is likely implementing enhanced security controls, wallet segregation, and possible reimbursement or insurance measures. No patch available; exchanges should review custodial wallet security and multi-signature protocols.
On September 24, 2026, at approximately 18:31 UTC, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets. In a statement shared on the social media platform X, the exchange confirmed that suspected North Korean threat actors were responsible for the theft of $351.6 million from its hot and warm wallet infrastructure. Bitget emphasized that its cold wallets and the overwhelming majority of platform assets remain secure. The incident marks one of the largest reported cryptocurrency exchange breaches of 2026, though details regarding the specific backend vulnerability exploited or the full extent of any user data compromise have not been disclosed. The attribution to North Korean actors is asserted by Bitget but has not been independently verified by external security researchers or agencies at the time of reporting.
Security Details
Unauthorized transfers from hot and warm wallets following a backend compromise. Cold wallets and majority of assets remain secure. Specific exploitation method not detailed in source.
Affected products
Bitget hot wallets, Bitget warm wallets
Mitigation
Bitget is likely implementing enhanced security controls, wallet segregation, and possible reimbursement or insurance measures. No patch available; exchanges should review custodial wallet security and multi-signature protocols.
Sources
The Hacker News
Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
Sep 25, 2026 · 10:35
Original link
Related Security News

Former US Air Force Members Sentenced to Prison for Business Email Compromise Scams
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. The sentencing, reported by BleepingComputer in September 2026, concluded a federal case targeting individuals who abused their military backgrounds to conduct financially motivated email fraud. The attacks spanned multiple years prior to sentencing, though specific victim counts and total financial losses were not detailed in the reporting. The case underscores the legal consequences of using military credentials and training for cyber-enabled fraud.




