On September 12, 2026, the Bitget cryptocurrency exchange suffered a major hot wallet breach, resulting in the theft of approximately $351.6 million (120,000 ETH and 6,000 BTC). The attack exploited a compromised backend Node.js signing script, backend/signing_service.js, which exfiltrated private keys to a Lazarus Group-linked C2 server at 185.141.63.122. Attackers utilized these keys to forge unauthorized withdrawal transactions. Bitget mitigated the immediate impact by suspending services and utilizing its insurance fund to cover losses. Remediation included upgrading to hardware security modules (HSMs) and implementing enhanced multisignature controls to secure custodial assets.
- Incident Overview: Breach Details
- Detected Sept 12, 2026, via anomalous large-value outflows on Ethereum and Bitcoin blockchains.
- Total losses estimated at $351.6M, specifically involving ~120k ETH and ~6k BTC.
-
Assets were transferred from primary hot wallets to a series of newly created, attacker-controlled addresses.
-
Attack Vector: Backend Exploitation
- Unauthorized modification of the
backend/signing_service.jsNode.js routine enabled private key exfiltration. - Stolen key material was transmitted to a command-and-control (C2) server at IP 185.141.63.122.
-
Attackers bypassed withdrawal logic by using the exfiltrated keys to sign and broadcast fraudulent transactions directly.
-
Threat Attribution: Lazarus Group
- On-chain forensic analysis ties the outflow addresses to known Lazarus Group Ethereum and Bitcoin wallets.
- The C2 infrastructure (185.141.63.122) is associated with prior North Korean state-sponsored cyber operations.
-
Attack demonstrates high sophistication by targeting specific exchange-side backend signing workflows.
-
Response & Technical Remediation
- Bitget suspended all deposits and withdrawals to contain the outflow and initiate forensic investigations.
- Financial impact was neutralized via the exchange's insurance fund, ensuring user asset protection.
-
Implemented mandatory hardware security module (HSM) usage and enhanced multisignature protocols for all hot wallet operations.
-
Market & Industry Impact
- The Bitget token (BGB) experienced a ~12% price drop within 24 hours of the breach announcement.
- The incident contributed to September 2026 being the highest month for recorded cryptocurrency exchange theft.
- Highlighted the critical necessity of backend code integrity monitoring and hardware-based key storage.
Related posts
- Cybersecurity News — Bitget Hot Wallet Hacked – Attackers Stole $351.6 Million From Hot Wallets
- The Hacker News — Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
- news.bitcoin.com — Bitget Hackers Drain $228M in 18 Minutes, Arkham Tracks 7 Chains
- techjacksolutions.com — Bitget Hot and Warm Wallets Breached, $351.6 Million Stolen; North Korean Hackers Suspected
- rapid7.com — Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772
- Cybersecurity News — Bitget Backend Breach Drains $387.5 Million as DPRK-Linked Launderers Expose Themselves
- techjacksolutions.com — Critical Citrix NetScaler Pre-Auth Command Injection (CVE-2026-88771) Actively Exploited; CISA Confirms Global Attacks Across Eight-CVE Bulletin
- Security Affairs — WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign
- BitSight Security Ratings Blog — CVE-2026-88771 and CVE-2026-88772: Two Critical Citrix NetScaler Flaws Under Active Exploitation
- techjacksolutions.com — North Korean Threat Actors Exploit Third-Party Security Appliance Zero-Day to Steal $387.5M from Bitget Across 11 Blockchains
- techjacksolutions.com — Bitget Cryptocurrency Exchange Loses $351.6M in Backend Authorization Bypass Attack; North Korean Involvement Assessed as Highly Likely by Elliptic and TRM Labs
- cybersecuritydive.com — Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts
- techjacksolutions.com — Bitget $388M Breach via Third-Party Security Product Zero-Day, Suspected TraderTraitor Attribution
- crypto.news — Bitget hack: Where did the stolen $387M go?
- Expert In the Cloud — When the Gateway Is Already Under Attack
- Bitcoinmagazine
- Coingabbar
- Altcoinbuzz
- Hackread
- Gulfnews
- Cyberkendra
- Tradingview
- Investing
- Cryptoslate
- The Record by Recorded Future — Crypto CEO accuses North Korea of stealing $387 million from Bitget platform
- Shattered
- Whale-alert
- Bitcoinfoundation
- Qz
- Thenextweb
- Scworld
- Tradingview
- Pymnts
- Tradingview
- Oodaloop
- Bitcoinmagazine
- Thestar
- Tomshardware
- thehackernews.com — Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
- Watchtowr
- Unit42
- blog.openvpn.net — NetScaler Zero-Days, Pentagon Breach & $387.5M Bitget Heist
- Coingeek
- Ground
- Kaseya
- Tradingview
- Gurufocus
- Dmarcreport