By using this site, you agree to the Privacy Policy and Terms of Use.
Accept

BTCRepublic: Timely News & Analysis for Smarter Trading.

  • ABOUT
  • DISCLAIMER
  • CONTACT
New Logo Black BTCRepublic BTCRebpublic-New White Logo
  • Home
  • Bitcoin News
  • Price Predictions
  • Guides
  • About
  • About
  • Contact
  • Privacy Policy
  • Disclaimer
  • Terms
Reading: Bitget Hack Update: North Korea Link, $387M Trail, and What Users Must Do
Share
Font ResizerAa
BTCRepublicBTCRepublic
  • Home
  • Bitcoin News
  • Price Predictions
  • Guides
  • About
Search
  • Home
  • Bitcoin News
  • Price Predictions
  • Guides
  • About
Follow US
  • About
  • Contact
  • Privacy Policy
  • Disclaimer
  • Terms
© 2025 All Rights Reserved by BTCRepublic.

Home - Bitcoin News - Bitget Hack Update: North Korea Link, $387M Trail, and What Users Must Do

Bitcoin News

Bitget Hack Update: North Korea Link, $387M Trail, and What Users Must Do

Charles Kibue
Last updated: October 5, 2026 6:25 am
Charles Kibue - Author
Published: October 5, 2026
Share
Disclosure: BTCRepublic provides analysis and forecasts but does not offer investment advice. Our content is for informational purposes only. Please conduct your own thorough research and consult with a financial advisor before making any investment in cryptocurrency.
Bitget hack news illustration, cracked padlock and stolen crypto tokens
SHARE

The Bitget hack just got a lot clearer, and the picture is worse than first reported. Bitget has confirmed that the September 24 theft of about $387.5 million came through a zero-day flaw in third-party security products, and blockchain intelligence firm Chainalysis has formally linked the attack to hackers tied to North Korea. That attribution pushes the total crypto stolen by North Korea-linked groups in 2026 past $1 billion, according to the firm’s October 1 report.

Why does this matter for you? This was not a simple exchange breach. The attackers sat inside Bitget’s wallet infrastructure for more than three weeks before moving a single coin, never touched a private key, and still walked away with nearly $388 million across four blockchains in about three hours. If you keep coins on any exchange, the lessons from this attack apply directly to your money.

btcrepublic advertise

Key Takeaways

  • Attack vector confirmed: attackers exploited a zero-day in unnamed third-party security products, with first malicious activity logged on August 31, three weeks before the Sept 24 theft.
  • $387.5 million gone in hours: 23 transfers moved the funds across Ethereum (49.7%), XRP Ledger (40.8%), Zcash (7.6%), and Tron (1.8%).
  • North Korea link: Chainalysis attributed the theft to DPRK-linked actors in its Oct 1 report, pushing 2026 North Korean crypto thefts past $1 billion.
  • Recovery looks slim: only about $1.1 million has been frozen; CEO Gracy Chen says the exchange does not expect to recover most of the funds.
  • Users are covered on paper: Bitget’s User Protection Fund, once worth over $464 million, absorbed the loss and was rebuilt above $300 million with company money.

What Bitget confirmed this week

The timeline got much sharper this week. In interim investigation reports published September 30 by security firms Mandiant and SlowMist, and in follow-up statements from Bitget on October 1, the exchange confirmed that the attackers did not break into its servers through a leaked password or a phishing email. Instead, they went through the very products meant to protect the exchange’s wallet infrastructure. Our original coverage of the Bitget hack in the first hours after detection documented the speed of the theft; what investigators have now added is how long the attackers were already inside.

Outline
    • Key Takeaways
  • What Bitget confirmed this week
    • The zero-day supply-chain attack path
  • Chainalysis points to North Korea
    • How $387 million moved in three hours
  • The laundering trail and why recovery looks slim
    • What the industry response reveals
  • Bitget’s response: withdrawals, protection fund, reserves
  • What everyday users should take from this
    • Five practical steps this week
  • FAQs
    • Were Bitget user funds affected by the hack?
    • How did attackers steal $387.5 million without private keys?
    • Has any of the stolen crypto been recovered?
    • Is Bitget safe to use now?
    • Why is North Korea suspected?
  • Conclusion

SlowMist traced the earliest malicious activity in available logs to August 31, meaning the attackers held internal access for more than three weeks before moving funds on September 24. Bitget’s systems flagged unauthorized transfers at 18:31 UTC that day, and the exchange initially estimated the loss at $351.6 million before raising it to $387.5 million after including additional Zcash and Tron transfers.

The zero-day supply-chain attack path

According to the published findings, the attackers first compromised two third-party security products used inside Bitget’s wallet stack. One of them carried a previously unknown zero-day vulnerability, a software weakness the vendor did not know about and had not fixed. Through that opening, the attackers gained privileged internal access, then reached the exchange’s production wallet systems.

The critical detail is what they did not need: private keys. Mandiant reported that the attackers bypassed Bitget’s standard customer-facing withdrawal process, manipulated transaction data, triggered the authorization process to approve fraudulent payouts, and then deleted traces after transferring the funds. Neither firm named the affected security products, and Bitget has declined to identify the vendors, citing security risks. The uncomfortable lesson is that the attacker’s path ran straight through security tooling. Trust in a vendor’s product, layered on top of trust in the exchange, became a single point of failure that nobody outside the company could see.

Chainalysis points to North Korea

On October 1, Chainalysis published the most detailed public account yet of how the money left the exchange, and it formally attributed the theft to North Korea-linked actors. The firm said the exchange and law enforcement partners worked from a round-the-clock war room as investigators followed the funds. Bitget CEO Gracy Chen had earlier described preliminary technical indicators as consistent with known North Korean hacking operations, but stopped short of a firm attribution. Chainalysis’s report is the first definitive public link.

btcrepublic advertise 2

The attribution matters beyond the headline. If the $387 million stands, North Korea-linked groups have stolen more than $1 billion in crypto in 2026 alone, which makes state-backed theft the single largest driver of this year’s losses. For context, crypto security losses reached about $1.26 billion in Q3 2026 across 247 incidents, per a CertiK data snapshot, and the Bitget theft alone represents roughly 31% of that entire quarter’s losses.

How $387 million moved in three hours

Chainalysis traced the initial exodus in detail. Within about three hours of the exploit, roughly $387 million left Bitget in just 23 transfers and landed on four chains: Ethereum received 49.7% of the outflows, the XRP Ledger took 40.8%, Zcash received 7.6%, and Tron accounted for the remaining 1.8%. Hundreds of transfers followed, with funds repeatedly shuttled between networks such as Ethereum and Bitcoin through bridges, mixers, and decentralized exchanges.

The XRP route drew particular scrutiny. Rather than sending stolen XRP to a centralized exchange where it could be frozen, the attackers pushed tens of millions of dollars through a cross-chain liquidity protocol and pulled Bitcoin out the other side. Chainalysis reconstructed that path over roughly a day and a half by matching deposits to their corresponding payouts. The firm also built custom AI-assisted tooling on its agentic platform to accelerate the tracing, compressing more than 20 hours of manual bridge reconciliation into under 10 minutes in one instance, while stressing that human investigators still defined the logic and reviewed the outputs.

Cross-chain fund flow across Ethereum, XRP, Zcash and Tron networks
Chainalysis breakdown: Ethereum 49.7%, XRP 40.8%, Zcash 7.6%, Tron 1.8% of the $387M outflow (Source: Chainalysis, Oct 1, 2026).

The laundering trail and why recovery looks slim

Separate on-chain work by security firm BlockSec mapped what happened after the initial exodus. The stolen assets were routed through Bitcoin, the THORChain cross-chain protocol, and CoinJoin mixing services, creating an obfuscation route that spans multiple networks and privacy tools. AMLBot separately traced 4 BTC from the hack to Wasabi CoinJoin, a non-custodial Bitcoin wallet with CoinJoin mixing built in. THORChain declined to block wallet addresses linked to the movement, citing its permissionless design, which left the cross-chain channel open to further movement.

This is the part that should reset expectations for anyone hoping the funds come back. Bitget CEO Gracy Chen has said the exchange does not expect to recover most of the stolen assets, and so far only about $1.1 million has been frozen. That is a fraction of one percent of the total. Once stolen coins pass through cross-chain swaps, privacy protocols, and mixers, tracing can continue indefinitely while recovery becomes a legal and technical long shot. Readers who want to understand how stolen cryptocurrency recovery actually works in practice will recognize this pattern: public ledgers make the theft visible, but they do not reverse a well-run exit.

What the industry response reveals

Chainalysis says it flagged the stolen funds in its data platform within minutes of identifying them, and that intelligence now helps exchanges, issuers, and law enforcement try to freeze or block the assets as the trail extends. Mandiant and SlowMist remain on the investigation, and Bitget says law enforcement agencies are involved. But the gap between tracing and recovery is the real story. A stolen-coin trail that everyone can watch, moving through protocols designed to never stop it, exposes a structural problem: transparency helps investigators, but it does not give victims their money back. That asymmetry is why exchange users, not just exchanges, need a plan.

Bitget’s response: withdrawals, protection fund, reserves

On the operational side, Bitget moved through a predictable playbook. It suspended withdrawals after detecting the transfers on September 24, then resumed them in phases: Bitcoin reopened on September 28, Ether on September 29, USDT on September 30, with other tokens, fiat, and peer-to-peer services scheduled for October 2. The company says the vulnerability has been fixed and that its cold wallets and private keys were never compromised.

The money question is the protection fund. At disclosure, Bitget said its User Protection Fund held 5,500 BTC, then worth more than $464 million, and would absorb the entire loss. On September 30, the exchange said it had replenished the fund to more than $300 million using its own capital, meeting a one-week pledge Chen made publicly. Chen’s statement was blunt: the financial impact is being absorbed by Bitget rather than passed on to users. Self-reported reserve ratios sat at 131% on September 29, with all 19 covered assets above 100%. These are the exchange’s own numbers, so they deserve the usual caution, but the direction of travel is clear: the company is paying to keep user balances whole rather than socializing the loss, a marked contrast with how the $235 million WazirX hack left Indian users waiting for years.

What everyday users should take from this

The analytical read here is that this attack broke the mental model most exchange users carry. The old model says: a strong exchange with big reserves and security vendors is safe enough. The new evidence says: attackers can compromise the security vendor itself, sit undetected for weeks, and drain hot and warm wallets without ever touching a private key. No amount of user-side caution, strong passwords, or two-factor authentication would have stopped this. The only variable a user fully controls is how much they leave on the exchange.

That is not an argument to avoid exchanges entirely. They are still the easiest on-ramps and the best place for active trading balances. It is an argument for sizing your exchange exposure like cash in a wallet: enough for what you need soon, not your life savings. The funds that are never on an exchange cannot be in an exchange’s hot wallet when the next zero-day lands. If you are still setting up your own storage, our guide on setting up a crypto wallet walks through the basics, and the follow-up on backing up a seed phrase safely covers the step most people get wrong.

Hardware wallet and seed phrase for Bitcoin self-custody

Five practical steps this week

  1. Shrink your exchange balances. Keep only what you actively trade. Move long-term holdings to wallets where you control the keys.
  2. Use self-custody for savings. Hardware or well-reviewed non-custodial wallets remove the counterparty entirely. A hardware wallet for large amounts is the single highest-leverage security upgrade.
  3. Write down your seed phrase on paper or metal. Store it offline, in more than one secure location. Never photograph it or save it in cloud notes.
  4. Check proof of reserves, but treat them as a signal, not a guarantee. Reserve ratios above 100% are better than nothing, but they are snapshots, not audits of internal security.
  5. Watch for phishing after a breach. Major hacks are routinely followed by fake “compensation” and “refund” scams. Bitget will not ask for your seed phrase or private keys. Ever.

FAQs

The most common questions readers are asking about the Bitget hack, the North Korea link, and what it means for their own crypto.

Were Bitget user funds affected by the hack?

Bitget says no. CEO Gracy Chen stated that user balances are unaffected and that the User Protection Fund is absorbing the full loss. The fund was rebuilt above $300 million with company capital on September 30.

How did attackers steal $387.5 million without private keys?

Investigators found the attackers exploited a zero-day in third-party security products to gain privileged internal access, then manipulated transaction data and forged withdrawal commands. They bypassed the normal withdrawal process entirely, which is why no private keys needed to be stolen.

Has any of the stolen crypto been recovered?

Only about $1.1 million has been frozen so far. Bitget does not expect to recover most of the funds, because they were moved through cross-chain protocols, mixers, and CoinJoin services that make seizure extremely difficult.

Is Bitget safe to use now?

Bitget says the vulnerability is fixed and withdrawals resumed in phases from late September. Whether any exchange is “safe” depends on your risk tolerance. The safest practice remains keeping only trading funds on exchanges and storing long-term holdings in self-custody wallets.

Why is North Korea suspected?

Chainalysis formally attributed the theft to North Korea-linked actors in its October 1 report, based on technical indicators and cross-chain tracing analysis. The firm reports that DPRK-linked groups have stolen more than $1 billion in crypto during 2026.

Conclusion

The Bitget hack is now the defining exchange breach of 2026: $387.5 million taken through a zero-day in the exchange’s own security tooling, attributed to North Korean actors, laundered across four blockchains and counting, with almost nothing recovered. The uncomfortable truth is that this attack succeeded precisely where users had no visibility and no defense. That is the lesson worth acting on. Reduce what you hold on exchanges, take self-custody of what you plan to keep, and treat every “compensation” message you receive this month as a scam until proven otherwise. The next zero-day is already out there. The question is only whether your coins will be in its blast radius when it lands.

El Salvador Supports Innovation As It Teaches Bitcoin Nodes In Schools
Hong Kong Bitcoin ETFs Assets Under Management Have Hit HK$2 Billion
Fidelity Moved 4,000 BTC From One Of Its Main Wallets After ETF Outflows
El Salvador Bitcoin Portfolio Touches $767M As BTC Surges To $123K
Cboe to Launch Bitcoin, Ethereum Perpetual Futures in November
TAGGED:bitgetbitget hackchainalysiscrypto exchange hacknorth korea

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
Subscription Form

By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Print
Avatar for Charles Kibue
ByCharles Kibue
Author
Follow:
Charles Kibue is a cryptocurrency journalist and market analyst covering blockchain, digital assets, Web3, and market trends. His work has been featured in InsideBitcoins, CoinNews, and other leading crypto publications, where he delivers accurate, timely, and well-researched reporting for a global audience.
Previous Article Bitcoin Jobs Report: weak US payrolls push Bitcoin past $87K as October Fed rate hike odds collapse Bitcoin Jobs Report: Weak US Payrolls Push BTC Past $87K as Fed Hike Odds Collapse
Next Article Glowing Bitcoin coin beside a central bank building as an interest-rate chart line moves across a stormy sky Bitcoin Fed Rate Cut Prediction: What Happens If the Fed Actually Cuts Rates?
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Subscribe to Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
Subscription Form

Grayscale Files S-1 With SEC To Convert Avalanche Trust Into Spot AVAX ETF
Grayscale Files S-1 With SEC To Convert Avalanche Trust Into Spot AVAX ETF
News
Mine Bitcoins For Free
How To Mine Bitcoins For Free? – Miners Should Know
Mining
Bitwise Crypto ETF Approved by Major Global Bank
Bitwise Crypto ETF Approved by Major Global Bank
News
Unstoppable Domains and NFT Workx Launch a Tokenized Identity Solution
Unstoppable Domains and NFT Workx Launch a Tokenized Identity Solution

Follow Us on Socials

BTCRepublic use social media to react to hot news, update supporters and share authentic and factful information

Facebook Twitter Linkedin Telegram Pinterest
New Logo Black BR


BTCRepublic is the go-to source for comprehensive news coverage on blockchain technology, cryptocurrencies, non-fungible tokens, and Web3 gaming. Our content ranges from market trends to in-depth price analysis, fresh developments, interviews, and beginner guides.

Subscribe to our newsletter

Stay ahead of the curve with the BTCRepublic newsletter. By subscribing, you will get information about what is happening in the Web3 world straight to your inbox.

Subscription Form (#3)

More

  • About
  • Contact
  • Privacy Policy
  • Disclaimer
  • Terms
Reading: Bitget Hack Update: North Korea Link, $387M Trail, and What Users Must Do
Share
© 2026 All Rights Reserved by BTCRepublic