At 18:31 UTC on 24 September 2026, Bitget's own authorization system started approving transfers to an attacker. By the time on-chain watchers noticed, the money was moving across seven chains. By the time the CEO posted, the number was $351.6 million. According to Bitget, not one private key had been stolen.
That last detail is the whole story. The Bitget hack is bigger than either of the two North Korea-linked heists that dominated the first half of 2026 (KelpDAO at $292 million and Drift at $285 million, per TRM Labs), but its size is not what should worry you. What should worry you is that it used the same move that emptied Bybit, DMM Bitcoin and KelpDAO: leave the keys alone and lie to whatever tells the keys what to sign.
This is a working analyst's read of the incident at roughly the 18-hour mark. You get what Bitget has confirmed, the attack chain as a diagram, the timeline, where the money went on-chain, why everyone is saying "Lazarus" and how much weight that label can actually bear, and what exchanges should change.
Status: updated 25 September 2026, 14:30 UTC. The investigation is less than a day old. Throughout, we separate what Bitget has confirmed, what analysts claim, and what is our own inference. Expect some numbers to move.
What Happened in the Bitget Hack
The Bitget hack is the theft of about $351.6 million from the hot and warm wallets of Bitget, one of the largest centralized crypto exchanges, detected on 24 September 2026. According to Bitget, the attacker compromised a backend system inside its wallet infrastructure, used it to spoof transaction data, and triggered the exchange's own authorization process to send funds out across seven blockchains. Bitget says private keys were not compromised, its cold wallets were untouched, and the loss is covered by its User Protection Fund. It suspects North Korean hackers. No government has confirmed that yet.
Here is the incident on one screen.
| Fact | What we know |
|---|---|
| Detected | 18:31 UTC, 24 September 2026 |
| Loss | ~$351.6M (Bitget's figure; trackers count ~$357M at their own prices) |
| What was hit | "A portion of the hot wallet and warm wallet layers" of a three-tier architecture |
| Chains | Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain, Base (trackers also see Tron) |
| Largest single asset | ~102.9M XRP, about $157M |
| Mechanism | Compromised wallet backend spoofed transaction data into Bitget's authorization process |
| Private keys | Compromise "ruled out" |
| Customers | Balances covered by a User Protection Fund of "over $464 million"; withdrawals paused, deposits and trading live |
| Responders | Mandiant and SlowMist; authorities notified |
| Attribution | Suspected DPRK (Bitget, preliminary). No government attribution. |
CEO Gracy Chen posted the notice on X at 21:30, and a near-identical version went up on Bitget's support center, timestamped 21:39. Read it closely and you can see the shape of the problem before Bitget ever described the mechanism: cold storage fine, hot and warm tiers bleeding, and a promise not to "speculate on the attack vector."

Figure 1: Bitget's official notice, trimmed to the confirmed facts and actions taken. Note the three-tier wallet language: the attacker reached the tiers that are allowed to sign quickly. Screenshot from the Bitget Support Center.
Three edits separate this page from the CEO's post. "The full amount of this loss" became "the loss relating to this platform-wide incident." "Law enforcement" became "relevant authorities." And the promises of hourly updates and a report within 24 hours are gone. None of that is a scandal. It is a reminder that in the first day of an incident, you should cite the exact document and timestamp you are quoting, because the documents themselves move.
The Bitget Hack Timeline, Hour by Hour
The best way to understand an incident is to lay three clocks side by side: when the attacker acted, when outsiders noticed, and when the victim spoke.

Figure 2: Three clocks on one axis: what moved on-chain, what public trackers saw, and what Bitget said. The shaded band is the theft window. Note how long the XRP Ledger leg ran, and how far early public estimates trailed the real number. Compiled from Bitget and CEO posts on X, bitget.com, WuBlockchain, CoinDesk, Decrypt and our own on-chain checks.
The theft window opened at 18:31 with a 0.84 ETH test transfer out of a Bitget hot wallet, per Unchained. The XRP started moving at 19:01. At about 19:34 a fresh address on Arbitrum received 19.67 million USDT0 and swapped it into 7,111 ETH through UniswapX and 1inch Fusion in about six minutes, overpaying by up to roughly 5%. Nobody overpays by 5% unless the alternative is losing the whole amount to a freeze.
The first public flag on X came at 19:57. Arkham analyst Emmett Gallic posted a $178 million estimate at 20:24 and raised it to $183 million at 20:35 (CoinDesk). The last visible EVM outflow landed at 20:55, on Avalanche, according to the WuBlockchain timeline recap. On the XRP Ledger, a Bitget wallet made its last payment to the attacker at 21:19, which we confirmed on-chain.
Bitget spoke at 21:30. Three hours after detection, the number jumped from the $180 million to $184 million that trackers could see to $351.6 million. The gap was mostly the XRP Ledger leg, which early trackers had not counted.
At 00:43 on 25 September, Chen posted the technical update that turned this from "exchange hacked" into a case study. By 07:10 Bitget had named its outside responders: Mandiant and SlowMist.
One gap deserves an honest flag. Bitget says its emergency response team was active "within minutes of detection." On-chain, Bitget wallets were still paying the attacker on the XRP Ledger at 21:19, nearly three hours after detection and eleven minutes before the public notice, and containment was not confirmed until 00:43. There are innocent explanations (transactions already signed and queued before the response kicked in, for instance). There is also a less comfortable one. We do not know yet, and neither does anyone writing with certainty about it.
How the Attack Worked: Draining an Exchange Without Stealing a Key
Most people picture an exchange hack as key theft: someone gets the seed phrase, empties the wallet. The Bitget hack does not fit that picture, and the difference is the most useful thing in this article.
A large exchange runs its wallets in tiers. Cold storage is offline and slow to move by design. Warm wallets refill the hot tier under separate approval. Hot wallets pay out customer withdrawals in seconds, so their keys have to be online, usually inside an HSM or an MPC signing cluster. Between the customer clicking "withdraw" and a signature coming out of that cluster sits a pipeline: a service creates the withdrawal, risk engines check it, and an authorization layer tells the signer "this one is approved, sign it."
In Chen's words, the attacker "compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out." And: "Private key compromise has been ruled out."
Put those two sentences together. The HSM or MPC cluster did its job perfectly. It signed what it was given. What it was given was forged.

Figure 3: Bitget's withdrawal pipeline and where the attacker entered it. The red path is the attack as Bitget has described it; the blue path is normal customer traffic, which Bitget says was not forged. Step 0 is the CEO's preliminary account (a compromised third-party tool) and is not yet confirmed. Diagram: CTI Academy.
Walk the chain from the top.
Step 0, initial access, is only partly disclosed. In her livestream, according to TechFlow, Chen said the preliminary assessment points to a supply chain attack: a third-party tool Bitget uses every day was breached, not its core systems, and that tool reached the wallet backend. She also said the final attack vector still needs confirmation, and Bitget has not named the tool or the vendor. We draw it dashed for that reason. How the tool itself was compromised is the open question. If this is TraderTraitor, the documented route into a vendor is a fake recruiter on LinkedIn or Telegram, a "coding challenge" that runs malware on an engineer's machine, and then stolen session tokens or cloud credentials (Unit 42; Wiz). That is a hypothesis to test, not a fact to repeat.
Step 1, a backend foothold, is confirmed. "A critical backend system within our wallet infrastructure." Bitget has not named the component. If the third-party account holds, this is the Bybit pattern again: the attacker never needed to break the exchange's own perimeter, only something the exchange already trusted.
Step 2, spoofed transaction data, is the heart of it. The attacker forged transfer data at the layer that feeds authorization. Chen added in her live Q&A that user withdrawal requests were not forged. So this was not a flood of fake customer withdrawals. It was the exchange's own internal plumbing, instructing its own signer to pay the attacker.
Step 3, authorization fires. Keys used as designed, never exfiltrated. If that assessment holds, it is genuinely good news for Bitget's cold storage, which should not need emergency rotation. It is bad news for everyone who thinks an HSM or MPC deployment is the end of the conversation. Hardware protects the key. It does nothing about the truth of the input.
Step 4, hot and warm wallets drained across seven chains, with the cold tier untouched. The tiering worked as a blast-radius limit. It did not work as a theft limit, because the hot and warm tiers held a third of a billion dollars.
Step 5, freezable assets dumped first. About $80 million of the roughly $88 million in USDT, USDC, USDT0 and XAUt was swapped into ETH within about 90 minutes of the first transfer. More on that below, because it tells you who you are dealing with.

Figure 4: The post that disclosed the mechanism, 00:43 UTC on 25 September. The key phrase is "spoof transaction data," and the key omission is how the attacker reached that backend. Source: @GracyBitget on X.
Where the Money Went: Following $351.6M On-Chain
The laundering so far splits cleanly into two very different behaviors, and the split is deliberate.

Figure 5: Two exits. On EVM chains the attacker raced to shed anything an issuer could freeze; on the XRP Ledger, where native XRP cannot be frozen, they slowed down. Tracker figures from Lookonchain, MistTrack, Unchained and Bitcoin.com; balances checked on-chain by CTI Academy on 25 September. Diagram: CTI Academy.
Start with what was taken. Bitget has not published a per-asset breakdown. Lookonchain's tally is the most complete public one:
| Asset | Amount | USD (tracker prices) |
|---|---|---|
| XRP | 102.93M | $157.48M |
| ETH | 31,890 | $85.75M |
| USDT | 34.75M | $34.75M |
| USDC | 21.05M | $21.05M |
| USDT0 (Arbitrum) | 19.67M | $19.67M |
| XAUt (tokenized gold) | 3,000 | $12.82M |
| BNB | 12,719 | $9.88M |
| AVAX | 821,012 | $8.38M |
| TRX | 20.59M | $7.07M |
That totals about $357 million, a little above Bitget's figure because of pricing and timing. No tracker has reported BTC or SOL taken.
On the EVM side, speed. Stablecoins and tokenized gold are the only assets here that a central issuer can freeze. The attacker treated them like they were on fire. The USDT0 went in six minutes once it landed. USDT, USDC and XAUt left the main exploiter address, which Etherscan tags "Bitget Exploiter 1" and PeckShield flagged at 20:31, and were swapped into roughly 22,600 ETH in about 40 minutes, per Unchained. Stargate and cBridge carried side-chain funds back to Ethereum. By 23:39, per Lookonchain, most of the EVM take sat as 67,982 ETH, about $183 million. Not all of it moved that fast: about 8.2 million USDC bridged to Avalanche at 20:55 was still sitting there hours later.
Then the attacker stopped. Two fresh addresses received exactly 10,000 ETH each at 20:13 and 20:19, and a third received 4,590 ETH at 21:41. When we checked them at 13:00 UTC on 25 September, all three were untouched, holding 10,000, 10,000 and about 4,596 ETH.
On the XRP Ledger, patience. Three payments between 19:01 and 21:19 moved 102.98 million XRP from two Bitget-labeled wallets into one consolidation account. That account then split the XRP into four wallets of 20 million and one of about 22.98 million, and each received a 0.00001 XRP dust payment, an address-poisoning pattern. Only one of the five has moved. It hops funds through freshly created accounts and out through Bridgers, the SWFT cross-chain swap service, into ETH. Our check at 13:00 UTC showed about 1.62 million XRP gone from it. The other four hold their full balances.
Why the difference? Native XRP cannot be frozen by anyone, so there was no clock. Stablecoins can be, and the clock was measured in minutes. The only freeze publicly identifiable so far proves the point: on-chain researchers report that Circle froze about 100,000 USDC, while roughly 218,000 USDT at the same address was still live at the time of that report. Against $88 million in freezable assets, that is a rounding error. Bitget says "a few" chain foundations have frozen attacker addresses, but it has not named the chains or the amounts.
What has not happened yet. No THORChain, no Tornado Cash, no Wasabi, no conversion to BTC, no OTC desk. That will probably change. After Bybit, Elliptic documented stolen tokens swapped to ETH within minutes, then ETH pushed through eXch (a no-KYC swapper that has since shut down) and other services into BTC and on into mixers. Chainalysis describes North Korean laundering as running in waves over roughly 45 days, with most volume moved in tranches under $500,000 and a preference for Chinese-language money-movement services, bridges and mixers. If that holds here, the dormant ETH is not abandoned. It is queued. The last leg of that pipeline, cash-out through brokers and mules, is the same economy we mapped in our piece on bulletproof hosting and the money mule ecosystem.
Attacker Addresses for Screening
For compliance teams screening deposits. Verify against live trackers before acting; labels change quickly. Bitget's own victim wallets (rGDre…4GzFn, rwTTs…obXLEf) are deliberately not listed.
| Chain | Address | Role | Labeled by |
|---|---|---|---|
| Ethereum | 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee |
Main exploiter address | Etherscan ("Bitget Exploiter 1"), PeckShield |
| Ethereum | 0xD2C2f029eFF5caCc686F24377CfdDcfc82d9F899 |
10,000 ETH, dormant | CTI Academy on-chain trace |
| Ethereum | 0x600cfeDc6Bd65Fa79B604dC44964f419e45784b2 |
10,000 ETH, dormant | CTI Academy on-chain trace |
| Ethereum | 0xDc2901f741B4003e32B8B752e97b8c4C1891dC63 |
4,596.47 ETH, dormant | CTI Academy on-chain trace |
| XRPL | rwNhefsz1UQEusxhCvHip3RANinWi4CTck |
XRP consolidation account | Identified by Unchained and Bitcoin.com; CTI Academy trace |
| XRPL | rDRV9nLg8xbLsafKZnhNgWuE1TiSLE95hs |
Split wallet, active | CTI Academy on-chain trace |
| XRPL | r3UGfDM4ZyFSCzKH7TQEjgago9QoUJagtJ |
Split wallet, 20M XRP | CTI Academy on-chain trace |
| XRPL | rH7oMFKBgdK99TPQctFVzddD7srRzyCqZn |
Split wallet, 20M XRP | CTI Academy on-chain trace |
| XRPL | rwSjBrtxBC75TqZ5YvJ1TGfaRpQvVNsAKw |
Split wallet, 20M XRP | CTI Academy on-chain trace |
| XRPL | r6NcwN3dR5ciyBv9XsLyMNc9Kg2FBCs7Y |
Split wallet, ~22.98M XRP | CTI Academy on-chain trace |
Addresses age fast. What will still be true next month is the behavior: freezable assets swapped at a premium within minutes, round-number tranches parked in fresh addresses, and a slow, custodial-service exit for the asset nobody can freeze.
Was It Lazarus? What the Evidence Actually Supports
Every headline says Lazarus. Here is what sits under that word.
What Bitget says. In the live Q&A, Chen said the team found "some IP addresses that match the VPN choices by a certain DPRK group." Bitget's written line is that "based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations" (The Hacker News; BleepingComputer). Bitget has also said it will not formally speculate until the investigation is complete.
What an outside analyst says. At 00:53 UTC on 25 September, on-chain analyst Specter posted that the stolen XRP "was bridged and can be directly linked to the funds stolen in the AFX hack" (TechFlow carried the claim soon after). AFX lost $24.15 million from an Arbitrum custody bridge after a fake "Oddium Lab" recruiter lured a developer, and its post-mortem says its findings are "consistent with independent attribution" to UNC4899, also known as TraderTraitor (crypto.news).
What the method says. The mechanism fits a pattern this actor has used repeatedly. More on that in the next section.
Now weigh it, the way you would in a real assessment.
VPN IP overlap is weak evidence on its own. Commercial VPN exit nodes are shared by thousands of unrelated users, so "this IP was used by a DPRK group" is only meaningful if it came with a narrow time window or a matching session fingerprint, and we have not been told either. The AFX link, as Bitcoin.com's reading of the graph shows, runs through a single ETH wallet holding about $4,300. A shared swap service could produce exactly that overlap without a shared operator. Mandiant and SlowMist have not confirmed it. No blockchain analytics firm has published on it. ZachXBT, who referred to it in passing as a DPRK exploit, said he has no current plans to monitor the case, so the usual independent trace is missing too. And no government has attributed anything.
The method match is the strongest leg, and even that is an argument from pattern, not from evidence inside Bitget's network.
So our read, in estimative language: DPRK responsibility is likely, on the combination of method, laundering behavior and victim profile. That it is TraderTraitor specifically is plausible but unconfirmed. What would move it to high confidence: an FBI public service announcement (the FBI named TraderTraitor for Bybit five days after the theft), Mandiant publishing malware or infrastructure overlaps, or laundering addresses converging with a known DPRK cluster. If you write this up for your own organization, our guide to writing a threat intel report nobody ignores covers how to carry that uncertainty without burying it.
"Lazarus" Is an Umbrella, Not a Group
"Lazarus Group" is how the press says "North Korean hackers." Inside the industry it is an umbrella over several distinct clusters that share a parent, the Reconnaissance General Bureau, but not necessarily operators, tooling or targets. The cluster that matters here goes by a different name at every vendor:
| Who uses the name | Name |
|---|---|
| US government (CISA, FBI) | TraderTraitor |
| Mandiant / Google | UNC4899 |
| Microsoft | Jade Sleet |
| Palo Alto Networks Unit 42 | Slow Pisces |
| Press shorthand | "Lazarus Group" |
Mandiant assesses with high confidence that UNC4899 is a cryptocurrency-focused element within the RGB. Unit 42 calls Slow Pisces a spin-off from Lazarus. CISA's advisory AA22-108A introduced the TraderTraitor name in 2022, originally for the trojanized crypto apps the actor pushed, and tied the activity to Lazarus Group, APT38 and BlueNoroff. Google's July 2026 renaming moved several North Korean groups to NEPTUNE cryptonyms, but UNC4899 kept its UNC label, so the Mandiant name above is still current.
Why does the precision matter? Because Radiant Capital (2024) used a very similar signer-deception idea, and Mandiant attributes it to a different DPRK cluster, UNC4736, also tracked as Citrine Sleet. Drift (2026) assessed its own attacker as the same actor behind Radiant, and TRM Labs describes that actor as distinct from TraderTraitor. Different cluster, different lures, different malware, different detections. JPCERT/CC makes this argument directly: track at subgroup level, or your warnings go to the wrong sector. We unpack the whole naming problem, including how one CrowdStrike name maps to four Microsoft ones, in Threat Actor Naming, Decoded.
The Same Playbook: Attack the Signing Step, Not the Key
Line up the big DPRK crypto heists of the last two and a half years and ask one question of each: what did the signer see?

Figure 6: DPRK-linked thefts that attacked the signing step, by loss, with who made each attribution. Five times the attacker owned whatever told the signer what to sign; at AFX it owned the signers outright. Only Bybit was bigger than Bitget. Diagram: CTI Academy.
- DMM Bitcoin, May 2024, $308 million. An employee at wallet vendor Ginco ran a "pre-employment test" from a fake LinkedIn recruiter. The attacker later manipulated a legitimate DMM transaction request. The FBI, the DoD Cyber Crime Center and Japan's National Police Agency attributed it to TraderTraitor.
- WazirX, July 2024, more than $230 million. According to WazirX, its custody provider Liminal's interface showed signers one transaction while they signed another; Liminal disputes that and says WazirX's own devices were compromised. Either way, hardware wallets and a destination allow-list were in place and did not help. The US, Japan and South Korea jointly attributed the theft to North Korea.
- Bybit, February 2025, $1.5 billion. A Safe{Wallet} developer's machine was compromised and AWS session tokens were hijacked (Safe's findings, via The Hacker News), then JavaScript injected into Safe's web UI swapped the transaction only when Bybit's cold wallet was signing (NCC Group). The FBI named TraderTraitor.
- KelpDAO, April 2026, $292 million. Poisoned internal RPC nodes fed a forged message to a single verifier while still answering monitoring correctly (LayerZero).
- AFX, July 2026, $24 million. A malicious Git config on a developer's machine, a planted plugin in the JFrog artifact repository, then the validators themselves. AFX says implants on them co-signed the theft; Halborn says the attacker obtained five of seven validator keys. This is the variant in the list: the attacker did not deceive the signers so much as own them.
- Bitget, September 2026, $351.6 million. A compromised backend spoofed transaction data into the exchange's own authorization.
Six victims, six different technologies, one target: the signing step. The industry spent years hardening the key: HSMs, MPC, multisig, hardware wallets. The attacker moved one step upstream, to whatever produces the thing being signed.
The money this pays for is not abstract. Chainalysis counted $2.02 billion stolen by North Korea in 2025, $6.75 billion all-time, and attributed 76% of service compromises that year to DPRK actors. TRM Labs put DPRK at 76% of all crypto hack value in 2026 through April. The Multilateral Sanctions Monitoring Team counted at least $2.8 billion stolen between January 2024 and September 2025, and the US Treasury states plainly that revenue from digital-asset heists supports the WMD and ballistic missile programs. If Bitget is confirmed, DPRK's 2026 total passes roughly $950 million by our own arithmetic (TRM's $577 million through April, plus AFX and Bitget), with a quarter of the year left.
Mapping the Bitget Hack to MITRE ATT&CK
For detection engineers, here is the chain as ATT&CK techniques, with an honest status column. The initial-access, execution and supply-chain IDs follow Wiz's TraderTraitor analysis of the actor's past operations; the rest are our mapping, including the impact rows built from Bitget's own description.
| Stage | Technique | ID | Status in the Bitget case |
|---|---|---|---|
| Initial access | Phishing: Spearphishing via Service (fake recruiter) | T1566.003 | Unknown. TraderTraitor staple |
| Execution | User Execution: Malicious File (coding test) | T1204.002 | Unknown |
| Initial access | Supply Chain Compromise (npm/PyPI, vendor software) | T1195.001 / .002 | Unknown. Vendor compromise seen at Bybit via Safe |
| Credential access | Steal Web Session Cookie | T1539 | Unknown. Session hijack seen at DMM's vendor |
| Lateral movement | Use Alternate Authentication Material: Application Access Token | T1550.001 | Unknown. AWS session tokens seen at Safe (Bybit) |
| Lateral movement | Software Deployment Tools | T1072 | Unknown. Seen at AFX (Ansible) |
| Impact | Data Manipulation: Transmitted Data Manipulation | T1565.002 | Confirmed in substance ("spoofed transaction data") |
| Impact | Financial Theft | T1657 | Confirmed |
Notice how much of the left side of the chain is "unknown." That is normal on day one, and it is the part a forensic report would fill in, if Bitget or its investigators publish one. Until then, hunt for the whole chain, not just the bit that made headlines.
What Exchanges and Defenders Should Change
None of this is exotic. It is the unglamorous work of refusing to trust your own plumbing.
Verify intent at the signer, independently. The signer, or a policy service sitting right beside it, should rebuild what it is about to sign from its own source of truth (the ledger of customer withdrawals, the treasury schedule) and refuse anything that does not match. If the only thing telling the signer what to sign is the system that was compromised, you have one point of failure wearing a hardware badge. LayerZero's KelpDAO report makes the same point about verifiers: no single data source, no single attester.
Enforce policy where the key lives, not in the UI. Destination allow-lists, per-asset and per-hour velocity caps, and a human quorum above a threshold. WazirX had an allow-list and still lost $230 million, because, by its own account, the lie happened in the interface above it. Policy that the signing cluster enforces itself survives a compromised dashboard.
Size hot wallets to hours, not days. Tiering limited Bitget's blast radius to the hot and warm layers, and that is worth something. But hot plus warm held over $350 million. A warm tier that refills the hot tier under slower, separate approval, with a hard cap on what the hot tier can hold, turns a nine-figure loss into an eight-figure one.
Treat wallet backends, their deployment tooling and the vendor tools that touch them as tier zero. At AFX the path to the validators ran through a JFrog build server and an Ansible management service; at Bitget, by the CEO's preliminary account, it ran through a third-party tool. Anything that can create, modify or relay a withdrawal, or deploy code to something that can, belongs in the same security tier as the keys: its own network, its own identity plane, change control, behavioral monitoring, and a vendor inventory you can actually cut off in minutes.
Harden the people near the signer. The recurring first step in this actor's operations is social: a recruiter, a coding test, a project to clone and run. Google's H1 2026 cloud threat reporting described a suspected UNC4899 intrusion that began with a file AirDropped from a personal device to a work laptop. SentinelOne has seen weaponized Terraform lock files. No take-home tests or unknown repositories on machines that can reach wallet infrastructure, full stop. The persuasion techniques behind those lures are covered in our breakdown of the psychological tactics used in social engineering.
Pre-wire the freeze. The USDT0 was gone in six minutes. Outflow anomaly alerting needs to fire in seconds, and the phone numbers for Tether, Circle and the relevant chain foundations need to be in the runbook before the incident, not found during it.
For threat intelligence teams: track the cluster, not the umbrella. A "Lazarus" watchlist that mixes TraderTraitor, UNC4736 and the fake IT worker schemes will give you the wrong lures to train on and the wrong infrastructure to block. Screen inbound deposits against the addresses above and watch for the dormant ETH to move, probably in waves.
What We Still Don't Know
An honest incident write-up says where the edges are.
- Initial access. The CEO's preliminary answer is a compromised third-party tool. Which tool, how it was breached, and how long the attacker sat inside it are all still open.
- The vendor. If the supply chain account is confirmed, Bitget joins Bybit (Safe{Wallet}) and DMM Bitcoin (Ginco) in the came-through-a-vendor column, and every other customer of that tool has a problem too.
- The outflow window. Why transfers were visible until 20:55 if the response team was active within minutes.
- Per-chain figures from Bitget. Only tracker numbers exist, and trackers include Tron where Bitget's chain list does not.
- The AFX link. Whether Specter's trace survives scrutiny from Mandiant, SlowMist or the analytics firms.
- Official attribution. Whether the FBI publishes a PSA, as it did for Bybit.
- Recovery. Chen says some attacker wallets were frozen, but the only verified freeze is about $100,000.
We will update this article if Bitget publishes its promised incident report or its investigators release findings. For the daily picture in between, todayincyber.io aggregates the coverage as it comes in.
Reading an Incident Like an Analyst
Anyone can repeat "Lazarus stole $351 million." The analyst's job starts at "how do we know, how sure are we, and what does it change for us." That means separating a victim's preliminary claim from a government attribution, reading a fund-flow graph for intent rather than just totals, and turning a headline into three controls someone can deploy on Monday.
Theory teaches you the frameworks. Judgment comes from reps: reading raw artifacts, weighing sources that disagree, writing the assessment under time pressure. That is what the Hunter track is built around, from Hunter I fundamentals through Hunter IV tradecraft, with the SOC Simulator putting you on the receiving end of the alerts this kind of attack should trigger. If you want to build that judgment on real cases, start with the CTI Academy courses. And if you are new to the field, our pillar guide on what cyber threat intelligence actually is is the right first stop.
Frequently Asked Questions
What happened in the Bitget hack?
On 24 September 2026, attackers stole about $351.6 million from Bitget's hot and warm wallets. According to Bitget, they compromised a backend system in the exchange's wallet infrastructure, used it to spoof transaction data, and triggered Bitget's own authorization process to send funds out across seven blockchains. Cold wallets were not affected.
How much was stolen in the Bitget hack?
Bitget puts the loss at approximately $351.6 million. Blockchain trackers count about $357 million at their own prices, led by roughly 102.9 million XRP (about $157 million) and 31,890 ETH (about $86 million), plus USDT, USDC, USDT0, tokenized gold, BNB, AVAX and TRX.
Was the Bitget hack carried out by the Lazarus Group?
It is suspected, not confirmed. Bitget says the method is "highly consistent" with North Korean hacker groups, citing VPN IP addresses and on-chain patterns, and one analyst has linked the stolen XRP to funds from a hack attributed to TraderTraitor, a North Korean cluster often lumped under "Lazarus." No government has attributed the attack, and Mandiant and SlowMist have not published findings.
Are Bitget users' funds safe after the hack?
Bitget says customer balances are fully covered by its User Protection Fund, which held over $464 million when the incident happened, and that cold wallets were untouched. Withdrawals were paused as a precaution while deposits and trading continued. The loss would consume roughly three quarters of that fund, and Bitget has said it will top it back up.
How did hackers steal from Bitget without the private keys?
They attacked the pipeline above the keys. The attacker controlled a backend system that feeds Bitget's authorization process, reportedly through a compromised third-party tool, forged the transaction data it passed along, and let Bitget's own signing infrastructure approve and sign the transfers. According to Bitget, the keys worked exactly as designed; the instructions they received were fake.
What is TraderTraitor?
TraderTraitor is the US government's name for a cryptocurrency-focused North Korean hacking cluster, tracked by Mandiant as UNC4899, by Microsoft as Jade Sleet and by Palo Alto Networks Unit 42 as Slow Pisces. It is part of the broader "Lazarus" umbrella under North Korea's Reconnaissance General Bureau, and the FBI has attributed the Bybit and DMM Bitcoin thefts to it.
How is the Bitget hack different from the Bybit hack?
Bybit lost about $1.5 billion from a cold wallet in February 2025 after attackers compromised a third-party vendor, Safe{Wallet}, and altered what Bybit's signers saw in the web interface. Bitget lost $351.6 million from hot and warm wallets through a compromised backend inside its own wallet infrastructure. The shared idea is signer deception: in both cases the keys signed what they were shown, and what they were shown was forged.
Can the stolen Bitget funds be frozen or recovered?
Only partly. Stablecoin issuers can freeze their tokens, and on-chain researchers report that Circle froze about $100,000 in USDC, but the attacker swapped most freezable assets into ETH within about 90 minutes. Native XRP, the largest single asset taken, cannot be frozen by anyone. Recovery will depend on catching funds at swap services, exchanges and OTC desks as they are laundered.
Sources
Bitget (primary) - Bitget Support Center: Security notice, 24 Sep 2026 - Gracy Chen on X: Security notice, 24 Sep 2026 - Gracy Chen on X: Technical update, 25 Sep 2026 - Gracy Chen on X: 12-hour summary, 25 Sep 2026 - Bitget on X: Mandiant and SlowMist engaged, 25 Sep 2026
Incident reporting and on-chain analysis - The Hacker News: Bitget says suspected North Korean hackers stole $351.6M - BleepingComputer: Hackers steal $351.6 million in Bitget crypto exchange hack - CoinDesk: Bitget says $352 million affected in a hack - CoinDesk: Bitget's hack happened via spoofed transfers, not private keys - Cointelegraph: Bitget CEO suspects North Korea, citing IP clues - Decrypt: Bitget hacked as funds vanish from exchange wallets - WuBlockchain: Bitget hacked suddenly, timeline recap - Unchained: Bitget's hot and cold wallets hit in suspected hack (early report; Bitget says cold wallets were not affected) - Bitcoin.com News: $157M in stolen XRP sits in wallets no one can freeze - CryptoSlate: Bitget's hack could drain 76% of its protection fund - ChainCatcher: Circle freezes USDC linked to the Bitget attacker - Specter on X: Bitget XRP linked to AFX hack funds - TechFlow: Specter links Bitget's stolen XRP to AFX hack funds - TechFlow: Behind Bitget's $351 million hack, supply chain attacks resurface - Lookonchain on X: 67,982 ETH consolidated - Lookonchain on X: Stolen asset breakdown - PeckShield on X: Exploiter address flagged - The Crypto Times: ZachXBT will not monitor the Bitget hack
Actor profile and precedents - FBI IC3: North Korea responsible for $1.5 billion Bybit hack - FBI, DC3 and NPA: TraderTraitor responsible for $308M DMM Bitcoin theft - CISA AA22-108A: TraderTraitor - Mandiant: North Korea leverages SaaS provider in supply chain attack (UNC4899) - Unit 42: Slow Pisces targets developers with coding challenges - Wiz: TraderTraitor deep dive - JPCERT/CC: Classifying Lazarus subgroups - NCC Group: In-depth technical analysis of the Bybit hack - US, Japan and ROK: Joint statement on DPRK cryptocurrency thefts - Cointelegraph: Liminal disputes WazirX's account of the hack - The Hacker News: Safe{Wallet} confirms TraderTraitor behind Bybit - Halborn: Explained, the AFX bridge hack - Unit 42: Threat actor groups tracked by Palo Alto Networks - LayerZero: KelpDAO incident report - crypto.news: AFX post-mortem and attribution - The Hacker News: UNC4899 breached crypto firm via AirDrop - SentinelOne: TraderTraitor backdoors resurface
Scale and funding - Chainalysis: 2025 crypto theft, North Korea drives record year - TRM Labs: North Korea stole 76% of all crypto hack value in 2026 - Elliptic: The Bybit hack money trail - US State Department: MSMT report on DPRK cyber activity - US Treasury: Sanctions on DPRK bankers laundering cybercrime proceeds