Cryptocurrency exchange Bitget reported a major theft of $351.6 million on September 24, 2026, allegedly perpetrated by North Korean state-sponsored hackers who compromised the platform's backend systems.

Bitget detected unauthorized transfers from its hot and warm wallets at 18:31 UTC. The exchange stated that cold storage wallets and the vast majority of platform assets remained unaffected, meaning the breach did not expose the entirety of user deposits. Hot wallets hold cryptocurrency actively used for trading and withdrawal operations, making them higher-risk targets than cold storage kept offline.

The attribution to North Korean threat actors follows a pattern established by groups including Lazarus, BlueNoroff, and associated North Korean units. These groups have systematized cryptocurrency theft as a revenue stream for the regime, stealing billions across the past decade. Previous North Korean operations targeting crypto exchanges include the 2014 Mt. Gox breach, the 2018 Coincheck hack ($530 million), and the 2022 Ronin Network compromise ($625 million).

Bitget's disclosure came swiftly, suggesting operational transparency following the discovery. The exchange did not immediately disclose the technical vector of the compromise, though the reference to "backend" access indicates attackers breached internal infrastructure rather than simply exploiting user-facing vulnerabilities. Backend compromise suggests either credential harvesting, privilege escalation, or supply chain infiltration that gave attackers direct database and wallet management access.

The $351.6 million figure makes this one of the largest crypto exchange thefts on record. The timing and sophistication align with known North Korean operational patterns. Intelligence reports have linked Lazarus and associated units to previous campaigns combining social engineering, supply chain attacks, and persistent network access to exfiltrate funds systematically.

For Bitget users, the breach creates immediate concerns. Exchange platforms typically operate as custodians of customer funds held in wallets segregated per user, though the exact architecture determines exposure levels. Users with holdings in hot wallets faced direct risk, while those relying on Bitget's custody model face secondary risk depending on whether the exchange maintains reserve coverage for losses.

Bitget likely faces regulatory scrutiny from multiple jurisdictions. South Korea, Singapore, the United States, and the European Union all regulate crypto platforms and expect rapid incident disclosure, customer notification, and third-party forensic investigation. The exchange will need to produce a detailed incident report, timeline, and remediation plan to maintain compliance and operator licenses.

The breach underscores persistent vulnerabilities in crypto exchange infrastructure. Hot wallets remain necessary for operational liquidity but create concentrated risk. Industry best practices now include multi-signature requirements, hardware security modules, and geographically distributed wallet systems. Advanced exchanges implement additional controls like rate-limiting on large withdrawals and behavioral analysis to detect anomalous transfer patterns earlier.

North Korean sanctions evasion through cryptocurrency theft generates capital for weapons development, financial operations, and elite programs. The U.S. Department of Treasury and international partners regularly sanction individuals and entities connected to these campaigns, though enforcement remains difficult when theft proceeds route through decentralized exchanges and mixers.

Bitget will likely announce compensation options, a security audit timeline, and operational improvements. Exchanges that recover quickly from breaches typically implement hardware wallet cold storage expansion and real-time anomaly detection systems.