North Korean Hackers Behind $351M Crypto Heist
A cyberattack attributed to North Korean hackers stole more than $351 million from cryptocurrency exchange Bitget, marking the biggest digital‑currency theft of 2026. Bitget halted withdrawals, citing a hot‑wallet breach, and the incident underscores the growing threat of state‑backed cybercriminal…
By Felo News Desk · Published
On Thursday, cryptocurrency exchange Bitget announced that it had fallen victim to a massive cyberattack that resulted in the theft of more than $351 million in digital assets. The breach, which involved the unauthorized transfer of funds from the platform’s hot wallets, is believed to have been carried out by a North Korean hacking collective, according to Bitget’s statements and analysis from blockchain intelligence firm TRM Labs.
What Happened
Bitget’s hot wallets—digital storage that is continuously connected to the internet to facilitate real‑time trading—were compromised, allowing attackers to siphon off a substantial portion of the exchange’s user funds. In response, Bitget immediately suspended all crypto withdrawals across its network to prevent further losses and to investigate the scope of the breach.
The company reported that its user protection fund, which holds $464 million, is sufficient to cover the loss. However, the exact timeline for when withdrawals will resume remains unclear, as Bitget’s CEO, Gracy Chen, has not provided a definitive date.
Background on the Attack
North Korean cyber operations have increasingly targeted the cryptocurrency industry, leveraging the anonymity and global reach of digital assets to funnel illicit proceeds. According to TRM Labs, North Korea is responsible for roughly three‑quarters of all crypto thefts recorded in 2026 to date. These attacks often follow a pattern of exploiting vulnerabilities in open‑source software, enabling attackers to mass‑hack victims and divert funds to support the country’s nuclear weapons program.
Bitget’s CEO described the breach as “highly consistent with known patterns of North Korean hacker organizations.” This characterization aligns with previous incidents, such as a $340 million theft earlier in September, where the attackers returned all but $47 million of the stolen funds. The Bitget heist surpasses that figure, making it the largest known crypto theft of the year.
Implications for the Crypto Ecosystem
The incident highlights the growing vulnerability of cryptocurrency exchanges, especially those that rely on hot wallets for liquidity. As the industry matures, regulators and exchanges are under increasing pressure to adopt more robust security measures, including multi‑factor authentication, cold storage solutions, and real‑time monitoring of wallet activity.
Moreover, the alleged involvement of a state‑backed actor raises concerns about the intersection of cybercrime and geopolitics. If confirmed, the theft could be part of a broader strategy by North Korea to fund its military ambitions, further complicating international efforts to curb illicit crypto flows.
Next Steps and Unresolved Questions
Bitget is currently conducting a forensic investigation to determine the full extent of the breach and to identify any additional vulnerabilities. The exchange has also engaged external security experts to audit its systems and to recommend improvements.
Key questions that remain include: When will withdrawals resume? How many users were affected? And what measures will Bitget implement to prevent a recurrence? The answers to these questions will shape the exchange’s response and the broader industry’s approach to security.
In the meantime, users are advised to monitor their accounts closely, change passwords, and enable two‑factor authentication wherever possible. The incident serves as a stark reminder that even the most established platforms are not immune to sophisticated cyber threats.
Industry Reactions
Regulators and industry bodies have called for greater transparency and cooperation among exchanges to share threat intelligence. Several analysts predict that the trend of state‑backed attacks on crypto platforms will continue, urging exchanges to adopt a “zero‑trust” security model.
While Bitget’s user protection fund is poised to cover the loss, the incident has sparked debate over the adequacy of such funds and whether they should be mandatory for all exchanges.
Key facts
- $351M stolen from Bitget via hot‑wallet breach
- Attack attributed to North Korean hackers
- Bitget’s $464M protection fund covers the loss
- Largest crypto theft of 2026, surpassing a $340M heist
- State‑backed actors use crypto to fund nuclear programs
- Industry calls for stronger security and transparency
Why it matters
The theft demonstrates the escalating threat of state‑backed cybercrime in the crypto industry, highlighting the need for stronger security measures and regulatory oversight to protect investors and maintain market confidence.
Frequently asked questions
What is a hot wallet?
A hot wallet is a digital wallet that is always connected to the internet, enabling quick transactions but also exposing it to higher security risks.
Will Bitget reimburse users?
Bitget’s user protection fund, which holds $464 million, is intended to cover losses from the theft, but the company has not yet confirmed the reimbursement process.
How can users protect themselves?
Users should enable two‑factor authentication, monitor account activity, and avoid transferring large amounts to unfamiliar addresses.
Sources
- [1] techcrunch.com — originally reported as “North Korean hackers suspected in $351M crypto theft, the largest so far this year”





