Chainalysis has attributed the theft of $387 million from cryptocurrency exchange Bitget to threat actors linked to North Korea. The incident occurred on September 24, 2026, when attackers compromised Bitget's backend system and manipulated transaction data to authorize unauthorized transfers from hot and warm wallets. While Chainalysis values the loss at $387 million, TRM Labs estimates it at approximately $351.6 million based on funds moved across seven blockchains. Bitget stated that its $464 million User Protection Fund would cover the losses, though no recovered funds have been confirmed as of early October.
The stolen assets were primarily XRP, which the attackers swapped for Bitcoin using the cross-chain liquidity protocol THORChain before distributing them through peel chains. This method involves spreading funds across sequential transfers to obscure their trail. Bitget CEO Gracy Chen cited IP addresses associated with a North Korean hacking group as evidence of the attribution. However, TRM Labs maintains a more cautious stance, noting on-chain links to previous North Korean incidents like Bybit and AFX Bridge but lacking definitive law enforcement confirmation. The attack pushed total crypto theft by North Korea-linked actors past $1 billion for the year.
This incident highlights a critical vulnerability in centralized exchange infrastructure: the compromise of authorization systems rather than cryptographic keys. By manipulating the data presented to approval processes, attackers bypassed traditional cold wallet security measures, forcing exchanges to rely heavily on internal controls and insurance funds like Bitget’s User Protection Fund. The discrepancy between Chainalysis and TRM Labs valuations underscores the ongoing challenges in accurately tracking multi-chain asset flows during rapid exploits, particularly when cross-chain protocols are used to launder proceeds into dominant assets like Bitcoin.
From an institutional adoption perspective, the scale of this theft reinforces the persistent risk premium associated with digital asset custody. As North Korea-linked actors continue to generate significant illicit revenue, regulatory scrutiny on exchange compliance and real-time monitoring capabilities will likely intensify. Market participants should watch for potential shifts in how exchanges structure their protection funds and whether insurers adjust premiums for platforms exposed to similar backend vulnerabilities. The lack of confirmed recovery also raises questions about the effectiveness of current international cooperation mechanisms in tracing and seizing state-sponsored cybercriminal assets.


