North Korean Hackers Allegedly Behind $351 Million Bitget Crypto Heist – Largest Theft of 2026
On Thursday, cryptocurrency exchange Bitget disclosed that its systems were compromised in a sophisticated cyberattack resulting in the unauthorized transfer of more than $351 million in digital assets. The breach, which targeted the exchange’s hot wallets—online storage solutions used for active trading—prompted an immediate suspension of all crypto withdrawals on the platform.
Details of the Breach
Bitget’s official statements on X (formerly Twitter) explained that the attackers gained access to hot wallet keys and moved funds out of the exchange’s custodial accounts. Hot wallets, by design, remain connected to the internet to facilitate rapid transactions, making them a frequent target for threat actors seeking large‑scale loot.
The company emphasized that it maintains a user protection fund valued at $464 million, a reserve intended to cover losses from incidents such as this one. Bitget’s leadership asserted that the fund’s size should be sufficient to absorb the financial impact of the theft and protect user balances.
Attribution to North Korean Cyber Units
Bitget CEO Gracy Chen linked the attack to known patterns exhibited by North Korean hacker groups. In her remarks, Chen stated that the breach was “highly consistent with known patterns of North Korean hacker organizations,” noting their history of targeting cryptocurrency infrastructure to generate revenue for the regime’s nuclear ambitions.
Supporting this claim, blockchain intelligence firm TRM Labs reported that North Korean actors are responsible for roughly three‑quarters of all cryptocurrency thefts recorded in 2026 to date. The firm’s data underscores a persistent trend whereby state‑sponsored cyber units from the Democratic People’s Republic of Korea exploit vulnerabilities in exchanges, decentralized finance protocols, and open‑source software.
Context Within the Wider Crypto Threat Landscape
The Bitget incident marks the largest known crypto heist of the year, surpassing a September 2026 attack that saw approximately $340 million stolen. In that earlier case, the perpetrator eventually returned all but $47 million of the stolen funds, a rare occurrence that highlighted the variability of attacker motives.
Industry analysts warn that the rising frequency and scale of such attacks underscore the need for enhanced security measures, including multi‑signature wallets, hardware‑based key management, and continuous monitoring of hot‑wallet activity. Exchanges are also urged to increase transparency around reserve funds and incident response protocols.
Next Steps and Unanswered Questions
As of the latest update, Bitget has not announced a timeline for restoring withdrawal services. The exchange continues to work with forensic investigators and law‑enforcement agencies to trace the moved assets and identify the individuals behind the operation.
While the user protection fund offers a financial safety net, the incident raises broader concerns about the resilience of centralized exchanges against sophisticated, state‑backed cyber threats. Stakeholders across the crypto ecosystem are watching closely to see how Bitget’s response will shape future security standards.