Chainalysis has attributed the September 24 Bitget breach, which resulted in approximately $387.5 million in losses, to North Korean-linked actors. This incident pushes the total value of crypto stolen by DPRK groups above $1 billion for 2026. Investigators traced the movement of stolen XRP through a cross-chain protocol into Bitcoin addresses controlled by the attackers, bypassing centralized exchanges.
The updated attribution follows earlier suspicions raised by Bitget CEO Gracy Chen regarding suspicious IP addresses connected to VPN services used by DPRK hacking groups. Bitget joins Drift Protocol and KelpDAO as major platforms hit by attacks linked to North Korea this year. The exchange revised its initial loss estimate to include previously uncounted Zcash and Tron transfers, confirming the vulnerability had been identified and fixed.
This development underscores the persistent threat posed by state-sponsored actors to cryptocurrency infrastructure, specifically highlighting the sophistication of money laundering techniques that utilize cross-chain liquidity protocols to obscure fund trails. By converting assets like XRP directly into Bitcoin without passing through centralized exchanges, attackers exploit gaps in traditional monitoring systems, challenging the efficacy of current compliance frameworks designed primarily for on-exchange transactions.
For institutional stakeholders, the incident serves as a critical reminder of operational risks associated with bridge technologies and cross-chain interoperability. As Chainalysis employs AI-driven tools to accelerate tracing efforts, the industry must prioritize enhanced coordination among cybersecurity firms, exchanges, and law enforcement to effectively monitor linked addresses and recover assets, thereby strengthening market credibility against sophisticated cyber threats.


