Bitget Acknowledges $351.6 Million Hack, Suspects North Korea’s Lazarus Group Involvement

Cryptocurrency exchange Bitget reported a significant security breach, revealing that attackers gained unauthorized access to part of its wallet infrastructure, resulting in the theft of approximately $351.6 million. The incident was detected on September 24, 2026, at 18:31 UTC, when the exchange’s security systems identified suspicious transfers from several hot wallets. In response, Bitget promptly suspended withdrawals, flagged the receiving addresses, and enlisted the assistance of law enforcement and blockchain security firms to address the breach.

Despite the severity of the incident, Bitget assured customers that trading and deposits were unaffected, and confirmed that customer balances remained intact with no impact on its cold wallets. According to Bitget’s CEO Gracy Chen, the stolen funds would be covered by the exchange’s User Protection Fund, which held more than $464 million at the time of the breach.

Further details emerged during a live broadcast where Chen stated that the breach appeared to be a direct attack on Bitget’s internal systems. Unlike many previous breaches where criminals forged withdrawal requests, this incident involved direct fund transfers from hot wallets, suggesting a sophisticated approach by the attackers. Chen emphasized that the attackers did not compromise users’ private keys or access Bitget’s cold storage, but the exact method of how they accessed the systems remains under investigation.

Speculation arose regarding whether an insider might have facilitated the breach. However, Chen clarified that the company does not currently view it as an inside job, even though investigators have not completely ruled out the possibility of employee complicity. She acknowledged the prevalence of insider threats in the cryptocurrency sector but noted that Bitget had not uncovered any evidence linking an employee to this particular incident.

In a surprising turn, Chen pointed to the possibility that the North Korean hacking group, Lazarus Group, was behind the attack. Known for orchestrating high-profile cryptocurrency heists, Lazarus has been implicated in previous thefts, including a $1.4 billion attack on Bybit in 2025. The group’s motives often revolve around funding North Korea’s economy, which is under heavy international sanctions. Chen shared her personal experience of a previous theft involving Lazarus, although she acknowledged that this does not substantiate their involvement in the current breach.

Despite the turmoil, Bitget reassured its customers that its User Protection Fund was sufficient to cover the losses, leaving a surplus of approximately $112.4 million after accounting for the theft. The company has not clarified whether it intends to utilize the fund immediately or how claims against it might be managed. As investigations continue, Bitget is working to track the affected funds through public blockchain transactions, although recovery will largely depend on whether the stolen assets can be traced back to cooperating exchanges.

In the coming days, Bitget has promised a comprehensive report detailing the cause of the breach along with corrective actions taken. Until such a report is released, questions remain about the specific vulnerabilities exploited and the nature of any connections to the Lazarus Group. As this incident unfolds, it serves as a stark reminder of the persistent cybersecurity threats faced by cryptocurrency exchanges, underscoring the need for robust security protocols to mitigate risks, particularly regarding initial access, persistence, and privilege escalation tactics as outlined in the MITRE ATT&CK framework.

Source