Chainalysis has attributed the theft of $387 million from cryptocurrency exchange Bitget to threat actors linked to North Korea. The incident occurred on September 24, 2026, when attackers compromised Bitget's backend system and manipulated transaction data to authorize unauthorized transfers from hot and warm wallets. While Chainalysis values the loss at $387 million, TRM Labs estimates it at approximately $351.6 million based on funds moved across seven blockchains. Bitget stated that its $464 million User Protection Fund would cover the losses, though no recovered funds have been confirmed as of early October.

The stolen assets were primarily XRP, which the attackers swapped for Bitcoin using the cross-chain liquidity protocol THORChain before distributing them through peel chains. This method involves spreading funds across sequential transfers to obscure their trail. Bitget CEO Gracy Chen cited IP addresses associated with a North Korean hacking group as evidence of the attribution. However, TRM Labs maintains a more cautious stance, noting on-chain links to previous North Korean incidents like Bybit and AFX Bridge but lacking definitive law enforcement confirmation. The attack pushed total crypto theft by North Korea-linked actors past $1 billion for the year.