In early October 2026, analytics firm Chainalysis attributed the September 24 breach of crypto exchange Bitget to actors linked to the Democratic People's Republic of Korea. The attack targeted a hot wallet, resulting in the outflow of around $387 million across 23 transfers within three hours. Following the incident, customers withdrew a net total of approximately $463 million, exceeding the value of the stolen assets.
The stolen funds were distributed across four blockchain networks: Ethereum (49.7%), XRP (40.8%), Zcash (7.6%), and Tron (1.8%). Chainalysis noted that obfuscation efforts involved bridges, cross-chain liquidity protocols, mixers, and decentralized exchanges. This attribution brings the total value of crypto thefts linked to DPRK groups in 2026 to over one billion dollars. Bitget subsequently replenished its protection fund to roughly $309 million, though this remains a voluntary reserve rather than a statutory guarantee.
This attribution underscores the persistent threat posed by state-backed actors to centralized cryptocurrency infrastructure. By targeting hot wallets, attackers exploit the structural necessity for exchanges to maintain online accessibility for withdrawals, turning operational convenience into a significant security vulnerability. The rapid outflow of $387 million highlights the limitations of real-time monitoring systems when faced with coordinated, high-volume attacks on custodial holdings.
From an institutional perspective, the incident reinforces the critical importance of custody models and regulatory frameworks like MiCA in Europe. While Chainalysis’s use of AI automation reduced bridge matching time from over 20 hours to under ten minutes, faster tracing does not necessarily prevent loss or ensure recovery. Investors must recognize that voluntary protection funds offer no legal assurance, making self-custody and diversified storage strategies essential for mitigating counterparty risk associated with large-scale breaches.


