Suspected North Korean Hackers Steal $351.6 Million from Bitget Exchange
Cryptocurrency platform targeted in large-scale wallet breach

Key Takeaways
- Bitget reported a $351.6 million theft from hot and warm wallets.
- The attack is attributed to suspected North Korean state-sponsored actors.
- The breach occurred prior to disclosure on September 25, 2026.
- Bitget is implementing enhanced security measures and wallet migration.
- The specific exploit vector remains under investigation.
Quick answers
- What happened?
- Bitget disclosed a security breach involving suspected North Korean state-sponsored actors who stole approximately $351.6 million from the exchange's hot and warm wallets. The incident is attributed to APT38 or a similar threat actor, though specific technical details of the exploit remain under investigation.
- Which products are affected?
- Bitget exchange hot wallets, Bitget exchange warm wallets
- What should defenders do?
- Bitget is implementing enhanced security measures, wallet migration, and potentially reimbursement plans. Users are advised to monitor official Bitget communications for updates on security improvements and fund safety. Exchange users should enable all available security features such as withdrawal whitelists and hardware-based authentication where available.
Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. The breach was identified and reported by the platform on September 25, 2026. The company attributed the attack to suspected North Korean state-sponsored actors, commonly associated with the APT38 group. The stolen funds were taken from the exchange's hot and warm wallet infrastructure. Bitget has stated it is implementing enhanced security measures, wallet migration, and potentially reimbursement plans for affected users. The specific exploit method details have not been publicly disclosed in the initial report. The incident highlights the ongoing risk of state-sponsored cryptocurrency heists targeting exchange infrastructure.
Security Details
The breach involved suspected North Korean state-sponsored actors stealing $351.6 million from Bitget's hot and warm wallets. The specific technical exploit method has not been detailed in the initial disclosure. The attack is attributed to APT38 or a similar threat actor. Bitget is implementing enhanced security measures and wallet migration in response.
Affected products
Bitget exchange hot wallets, Bitget exchange warm wallets
Mitigation
Bitget is implementing enhanced security measures, wallet migration, and potentially reimbursement plans. Users are advised to monitor official Bitget communications for updates on security improvements and fund safety. Exchange users should enable all available security features such as withdrawal whitelists and hardware-based authentication where available.
Sources
BleepingComputer
Hackers steal $351.6 million in Bitget crypto exchange hack
Sep 25, 2026 · 08:33
Original link
Related Security News

Former US Air Force Members Sentenced to Prison for Business Email Compromise Scams
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. The sentencing, reported by BleepingComputer in September 2026, concluded a federal case targeting individuals who abused their military backgrounds to conduct financially motivated email fraud. The attacks spanned multiple years prior to sentencing, though specific victim counts and total financial losses were not detailed in the reporting. The case underscores the legal consequences of using military credentials and training for cyber-enabled fraud.




