crypto-crime • The Hacker News

Bitget: Mistænkte nordkoreanske hackere stjal 351,6 millioner dollar efter backend-indbrud

Bitget siger, at mistænkte nordkoreanske aktører stjal 351,6 millioner dollar. Mandiant og SlowMist undersøger.

Bitget: Mistænkte nordkoreanske hackere stjal 351,6 millioner dollar efter backend-indbrud

Cryptocurrency exchange Bitget said on September 25, 2026, that suspected North Korean threat actors stole $351.6 million after compromising a critical part of the exchange backend. Security systems flagged unauthorized transfers from a limited set of hot and warm wallets at 18:31 UTC on September 24. Cold wallets and the overwhelming majority of platform assets remain secure, Bitget said. Customer balances are described as accurate; deposits and trading continue, while withdrawals are temporarily suspended during a comprehensive security review. Bitget has engaged Mandiant (Google) and SlowMist for independent forensic investigation.

CEO Gracy Chen said affected assets include ETH, XRP, BNB, AVAX, USDT and USDC across Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Smart Chain and Base. Bitget contacted chain foundations; some confirmed freezing of attacker addresses. Based on IP behaviour patterns and on-chain analysis, the company called the method "highly consistent" with known North Korean hacking organisations. The attacker compromised a critical backend system in wallet infrastructure, spoofed transaction data and triggered authorization to move funds. No further unauthorized transfers are possible, Bitget said; the exact intrusion method remains under investigation.

Bitget Wallet — the self-custodial wallet app — runs on separate infrastructure and was not affected. That distinction matters for users who conflate the exchange's custodial layer with the standalone wallet product. The incident comes about a week after SentinelOne attributed North Korea-linked TraderTraitor to an attack on an India-based IT services firm. TraderTraitor is best known for the $1.5 billion Bybit theft and $292 million taken from KelpDAO's LayerZero bridge. Whether Bitget is ultimately attributed to the same cluster or a neighbouring DPRK unit, the pattern confirms crypto platforms remain priority targets for state-backed financing.

For Nordic retail and institutional traders the practice is simple but uncomfortable: limit exchange balances, withdraw to self-custody when feasible, and treat urgent "security" messages during incidents with suspicion. For exchanges and custody providers the case underlines hard separation between signing infrastructure and application backends, multi-party approval for large withdrawals, and rapid cross-chain freeze coordination.

What crypto customers should do now

1. Verify Bitget account statements and pause large deposits until the investigation clarifies. 2. Move surplus to self-custody wallets you control — do not confuse Bitget Wallet with exchange hot wallets. 3. Ignore phishing claiming to "help" with withdrawal freezes; use only official domains. 4. Enable hardware-key/MFA and audit API keys; revoke unused keys. 5. Institutions: document exposure and notify compliance/insurance per internal playbooks.

Evidence Rail

  • Confirmed: Bitget public incident statements; Mandiant/SlowMist engaged; listed chains and asset types.
  • Reported: CEO assessment of North Korean TTP consistency; foundation freezes.
  • Unconfirmed: Final attribution to a named DPRK group (e.g. TraderTraitor) and exact initial access.

In Brief

  • $351.6 million left Bitget hot/warm wallets on September 24 after a backend compromise.
  • Cold wallets, customer balances and Bitget Wallet are reported unaffected; withdrawals paused.
  • Suspected North Korean link — the pattern echoes prior mega-thefts against crypto infrastructure.

Kilder og referencer

← Alle nyheder Værktøjer