Cybersecurity News • 2h
Bitget Backend Breach Drains $387.5M as DPRK‑Linked Launderers Expose Themselves
On 24 September 2026 at 18:31 UTC, Bitget’s monitoring detected unauthorized outflows from a limited set of hot and warm wallets, resulting in the transfer of roughly $387.5 million in stablecoins and tokens. Attackers leveraged VPN exit nodes historically tied to the Lazarus Group to obscure origin IPs, executed rapid stablecoin‑to‑ETH swaps to impede freezing, and funneled proceeds through known DPRK‑associated mixers and cross‑chain bridges. Bitget halted user withdrawals, activated its User Protection Fund (>$464 million) to cover losses, and began cooperating with blockchain analysts for attribution and tracing.