← Back to Daily Briefing (#SupplyChain)

Bitget Hot Wallet Compromise: $351.6M Stolen

Published September 27, 2026

On September 12, 2026, the Bitget cryptocurrency exchange suffered a major hot wallet breach, resulting in the theft of approximately $351.6 million (120,000 ETH and 6,000 BTC). The attack exploited a compromised backend Node.js signing script, backend/signing_service.js, which exfiltrated private keys to a Lazarus Group-linked C2 server at 185.141.63.122. Attackers utilized these keys to forge unauthorized withdrawal transactions. Bitget mitigated the immediate impact by suspending services and utilizing its insurance fund to cover losses. Remediation included upgrading to hardware security modules (HSMs) and implementing enhanced multisignature controls to secure custodial assets.

  • Incident Overview: Breach Details
  • Detected Sept 12, 2026, via anomalous large-value outflows on Ethereum and Bitcoin blockchains.
  • Total losses estimated at $351.6M, specifically involving ~120k ETH and ~6k BTC.
  • Assets were transferred from primary hot wallets to a series of newly created, attacker-controlled addresses.

  • Attack Vector: Backend Exploitation

  • Unauthorized modification of the backend/signing_service.js Node.js routine enabled private key exfiltration.
  • Stolen key material was transmitted to a command-and-control (C2) server at IP 185.141.63.122.
  • Attackers bypassed withdrawal logic by using the exfiltrated keys to sign and broadcast fraudulent transactions directly.

  • Threat Attribution: Lazarus Group

  • On-chain forensic analysis ties the outflow addresses to known Lazarus Group Ethereum and Bitcoin wallets.
  • The C2 infrastructure (185.141.63.122) is associated with prior North Korean state-sponsored cyber operations.
  • Attack demonstrates high sophistication by targeting specific exchange-side backend signing workflows.

  • Response & Technical Remediation

  • Bitget suspended all deposits and withdrawals to contain the outflow and initiate forensic investigations.
  • Financial impact was neutralized via the exchange's insurance fund, ensuring user asset protection.
  • Implemented mandatory hardware security module (HSM) usage and enhanced multisignature protocols for all hot wallet operations.

  • Market & Industry Impact

  • The Bitget token (BGB) experienced a ~12% price drop within 24 hours of the breach announcement.
  • The incident contributed to September 2026 being the highest month for recorded cryptocurrency exchange theft.
  • Highlighted the critical necessity of backend code integrity monitoring and hardware-based key storage.

Related posts

  1. Cybersecurity News — Bitget Hot Wallet Hacked – Attackers Stole $351.6 Million From Hot Wallets
  2. The Hacker News — Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
  3. news.bitcoin.com — Bitget Hackers Drain $228M in 18 Minutes, Arkham Tracks 7 Chains
  4. techjacksolutions.com — Bitget Hot and Warm Wallets Breached, $351.6 Million Stolen; North Korean Hackers Suspected
  5. rapid7.com — Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772
  6. Cybersecurity News — Bitget Backend Breach Drains $387.5 Million as DPRK-Linked Launderers Expose Themselves
  7. techjacksolutions.com — Critical Citrix NetScaler Pre-Auth Command Injection (CVE-2026-88771) Actively Exploited; CISA Confirms Global Attacks Across Eight-CVE Bulletin
  8. Security Affairs — WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign
  9. BitSight Security Ratings Blog — CVE-2026-88771 and CVE-2026-88772: Two Critical Citrix NetScaler Flaws Under Active Exploitation
  10. techjacksolutions.com — North Korean Threat Actors Exploit Third-Party Security Appliance Zero-Day to Steal $387.5M from Bitget Across 11 Blockchains
  11. techjacksolutions.com — Bitget Cryptocurrency Exchange Loses $351.6M in Backend Authorization Bypass Attack; North Korean Involvement Assessed as Highly Likely by Elliptic and TRM Labs
  12. cybersecuritydive.com — Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts
  13. techjacksolutions.com — Bitget $388M Breach via Third-Party Security Product Zero-Day, Suspected TraderTraitor Attribution
  14. crypto.news — Bitget hack: Where did the stolen $387M go?
  15. Expert In the Cloud — When the Gateway Is Already Under Attack
  16. Bitcoinmagazine
  17. Coingabbar
  18. Altcoinbuzz
  19. Hackread
  20. Gulfnews
  21. Cyberkendra
  22. Tradingview
  23. Investing
  24. Cryptoslate
  25. Reddit
  26. The Record by Recorded Future — Crypto CEO accuses North Korea of stealing $387 million from Bitget platform
  27. Shattered
  28. Whale-alert
  29. Bitcoinfoundation
  30. Qz
  31. Thenextweb
  32. Scworld
  33. Tradingview
  34. Pymnts
  35. Tradingview
  36. Oodaloop
  37. Bitcoinmagazine
  38. Thestar
  39. Tomshardware
  40. Reddit
  41. thehackernews.com — Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
  42. Watchtowr
  43. Unit42
  44. blog.openvpn.net — NetScaler Zero-Days, Pentagon Breach & $387.5M Bitget Heist
  45. Coingeek
  46. Ground
  47. Kaseya
  48. Tradingview
  49. Gurufocus
  50. Dmarcreport

LINK COPIED TO CLIPBOARD