Bitget Suffers $387.5 Million Theft in Largest Crypto Hack of 2026

The cryptocurrency exchange Bitget has confirmed a major security breach resulting in the theft of approximately $387.5 million in digital assets. According to the security intelligence firm TRM Labs, this incident marks the largest cryptocurrency theft by value recorded so far in 2026.

Security Breach and Financial Impact

Bitget initially estimated the loss at $351.6 million on September 24. This figure was later revised upward to $387.5 million to include additional affected assets identified on the Zcash and TRON networks. The exchange stated that the incident was contained and that no further unauthorized transfers occurred following the initial breach. While the company suspended withdrawal services to conduct security reviews and remediation, it emphasized that user funds remain protected by its User Protection Fund, which holds more than $464 million.

Attack Methodology and Investigation

The breach was detected by Bitget’s systems at 18:31 UTC on September 24, when unauthorized transfers were identified from a limited number of hot and warm wallets. Cold wallets, which store the majority of the platform’s assets offline, remained secure.

Bitget CEO Gracy Chen explained that the attackers did not steal private keys. Instead, they targeted a backend system linked to the wallet infrastructure. By manipulating transaction data reaching the authorization system, the attackers made malicious transfers appear legitimate, effectively tricking the authorization layer into approving the transactions.

During a livestream on X, Chen noted that the company suspects a North Korean hacking group may be responsible for the breach. This suspicion is based on the identification of IP addresses linked to VPN services previously associated with the group, as well as attack patterns similar to past incidents attributed to North Korea.

Read more:  Каждый третий владелец квартиры на Манхэттене потерял деньги при ее продаже в прошлом году

Independent investigations into the breach are currently being conducted by Mandiant and SlowMist. Analysts at TRM Labs observed that the stolen funds were quickly fragmented into new addresses and moved across various protocols to complicate recovery efforts.

Ещё по этой теме