← Back to Daily Briefing

Bitget Hot Wallet Compromise: $351.6M Stolen

Published September 27, 2026

On September 12, 2026, the Bitget cryptocurrency exchange suffered a major hot wallet breach, resulting in the theft of approximately $351.6 million (120,000 ETH and 6,000 BTC). The attack exploited a compromised backend Node.js signing script, backend/signing_service.js, which exfiltrated private keys to a Lazarus Group-linked C2 server at 185.141.63.122. Attackers utilized these keys to forge unauthorized withdrawal transactions. Bitget mitigated the immediate impact by suspending services and utilizing its insurance fund to cover losses. Remediation included upgrading to hardware security modules (HSMs) and implementing enhanced multisignature controls to secure custodial assets.

  • Incident Overview: Breach Details
  • Detected Sept 12, 2026, via anomalous large-value outflows on Ethereum and Bitcoin blockchains.
  • Total losses estimated at $351.6M, specifically involving ~120k ETH and ~6k BTC.
  • Assets were transferred from primary hot wallets to a series of newly created, attacker-controlled addresses.

  • Attack Vector: Backend Exploitation

  • Unauthorized modification of the backend/signing_service.js Node.js routine enabled private key exfiltration.
  • Stolen key material was transmitted to a command-and-control (C2) server at IP 185.141.63.122.
  • Attackers bypassed withdrawal logic by using the exfiltrated keys to sign and broadcast fraudulent transactions directly.

  • Threat Attribution: Lazarus Group

  • On-chain forensic analysis ties the outflow addresses to known Lazarus Group Ethereum and Bitcoin wallets.
  • The C2 infrastructure (185.141.63.122) is associated with prior North Korean state-sponsored cyber operations.
  • Attack demonstrates high sophistication by targeting specific exchange-side backend signing workflows.

  • Response & Technical Remediation

  • Bitget suspended all deposits and withdrawals to contain the outflow and initiate forensic investigations.
  • Financial impact was neutralized via the exchange's insurance fund, ensuring user asset protection.
  • Implemented mandatory hardware security module (HSM) usage and enhanced multisignature protocols for all hot wallet operations.

  • Market & Industry Impact

  • The Bitget token (BGB) experienced a ~12% price drop within 24 hours of the breach announcement.
  • The incident contributed to September 2026 being the highest month for recorded cryptocurrency exchange theft.
  • Highlighted the critical necessity of backend code integrity monitoring and hardware-based key storage.

Related posts

  1. Cybersecurity News — Bitget Hot Wallet Hacked – Attackers Stole $351.6 Million From Hot Wallets
  2. The Hacker News — Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
  3. news.bitcoin.com — Bitget Hackers Drain $228M in 18 Minutes, Arkham Tracks 7 Chains
  4. techjacksolutions.com — Bitget Hot and Warm Wallets Breached, $351.6 Million Stolen; North Korean Hackers Suspected
  5. techjacksolutions.com — Bitget Cryptocurrency Exchange Loses $351.6M in Backend Authorization Bypass Attack; North Korean Involvement Assessed as Highly Likely by Elliptic and TRM Labs
  6. Bitcoinmagazine
  7. Coingabbar
  8. Altcoinbuzz
  9. Hackread
  10. Gulfnews
  11. Cyberkendra
  12. Tradingview
  13. Investing
  14. Cryptoslate
  15. Reddit
  16. The Record by Recorded Future — Crypto CEO accuses North Korea of stealing $387 million from Bitget platform
  17. Shattered
  18. Whale-alert
  19. Bitcoinfoundation
  20. Qz
  21. Thenextweb
  22. Scworld
  23. Tradingview
  24. Pymnts
  25. Tradingview

LINK COPIED TO CLIPBOARD