Bitget Backend Breach Drains $387.5M as DPRK‑Linked Launderers Expose Themselves
On 24 September 2026 at 18:31 UTC, Bitget’s monitoring detected unauthorized outflows from a limited set of hot and warm wallets, resulting in the transfer of roughly $387.5 million in stablecoins and tokens. Attackers leveraged VPN exit nodes historically tied to the Lazarus Group to obscure origin IPs, executed rapid stablecoin‑to‑ETH swaps to impede freezing, and funneled proceeds through known DPRK‑associated mixers and cross‑chain bridges. Bitget halted user withdrawals, activated its User Protection Fund (>$464 million) to cover losses, and began cooperating with blockchain analysts for attribution and tracing.
- Incident Overview
- Unauthorized transfers involved specific hot/wallet addresses logged internally; cold wallets remained untouched.
- Approximately $387.5 million moved within minutes, exceeding prior 2026 crypto‑exchange theft records.
-
Withdrawals suspended platform‑wide pending forensic investigation; user reimbursement guaranteed via the Protection Fund.
-
Attack Vector & TTPs
- Initial compromise inferred from hot‑wallet private‑key exposure, consistent with Lazarus credential‑stealing malware targeting admin consoles.
- Attackers routed traffic through VPN exit nodes previously identified in Tom’s Hardware analysis as Lazarus infrastructure.
- Funds were instantly swapped from stablecoins (USDT, USDC, etc.) to ETH via decentralized exchanges to evade asset freezes.
-
Laundering employed mixers and cross‑chain bridges (e.g., Thorchain, Synapse) linked to known DPRK clusters per Chainalysis tracking.
-
Threat Attribution & Scale
- IP addresses, VPN usage, and rapid‑swap tactics mirror prior Lazarus operations, yielding high confidence in DPRK linkage.
- The theft pushes the cumulative DPRK‑linked crypto haul past $1 billion, marking a significant escalation in state‑sponsored cybercrime.
-
The Record Media and multiple analysts attribute the breach to North Korean threat actors based on observed patterns and scale.
-
Indicators of Compromise & Defensive Actions
- IOCs: hot‑wallet addresses (internal logs), recipient wallet addresses flagged by Chainalysis, VPN IP ranges tied to Lazarus, transaction hashes showing stablecoin→ETH swaps.
- Defensive measures: isolation of affected wallets, cooperation with blockchain analytics firms, activation of User Protection Fund, ongoing withdrawal freeze, and engagement with FINCEN/SEC for potential sanctions enforcement.
-
Monitoring recommendations: watch for ETH inflows to known DPRK mixer addresses, anomalous VPN login patterns from exchange admin IPs, and rapid token‑to‑ETH swaps on DEXes.
-
Conclusion
- The Bitget incident underscores the persistent risk of hot‑wallet key compromise and the sophistication of Lazarus‑style operational security.
- While the User Protection Fund mitigated direct user loss, the breach highlights the need for stronger privileged‑access controls, hardware‑based key management, and real‑time VPN‑traffic anomaly detection in crypto exchanges.
- Continued blockchain tracing and international regulatory coordination will be critical to disrupt the laundering pipeline and deter future DPRK‑linked cyber heists.
Related posts
- Cybersecurity News — Bitget Backend Breach Drains $387.5 Million as DPRK-Linked Launderers Expose Themselves
- Hackread
- The Hacker News — Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
- The Record by Recorded Future — Crypto CEO accuses North Korea of stealing $387 million from Bitget platform
- Pymnts
- Oodaloop
- Bitcoinmagazine
- Thestar
- Tomshardware