Incident
Published 2026-09-24
Verified 2026-09-27

Bitget hot/warm wallets (24 Sep): ~US$351.6M; CEO cites NK-consistent tradecraft; backend compromised, keys intact

Bitget Support Center security notice (published 24 September 2026 21:39; detected 18:31 UTC same day) confirms unauthorized transfers from portions of its hot and warm wallet layers totaling about US$351.6 million across ETH, XRP, BNB, AVAX, USDT and USDC. Cold wallets remain fully secure; Bitget Wallet (self-custodial) stated unaffected. UPDATE 25 Sep: CEO Gracy Chen (X) said IP behaviour and on-chain analysis are highly consistent with known patterns of North Korean hacker organizations (no named APT; evidence not published); some attacker-linked addresses frozen by blockchain foundations; Bitget says a critical backend wallet-infrastructure system was compromised to approve fraudulent transfers while private keys were not compromised; Mandiant and SlowMist assisting. Withdrawals paused pending review; account balances stated accurate; loss said within User Protection Fund (>US$464M). Primary: Bitget security notice; CEO attribution: SecurityWeek / THN 25 Sep 2026.

Product
Bitget cryptocurrency exchange (hot / warm wallet layers)
Versions
n/a (platform incident; cold wallets stated intact)
Exploited in Australia?
unknown
Patch to
Customers: use only verified Bitget channels; expect phishing around the withdrawal pause; monitor official notice for root-cause report and withdrawal restore. Operators of similar exchanges: review hot-wallet signing paths, third-party tooling / supply-chain controls, and protection-fund liquidity.

Primary: Bitget Support — [SECURITY NOTICE] hot wallets incident (24 Sep 2026) · Vendor: Bitget (vendor security notice) · SecurityWeek — NK suspected in Bitget heist; CEO + backend details (25 Sep 2026)

breaches cloud identity