Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
AI-Powered Attack Tool Exposed: Threat Actors Left Control Panel Unsecured
September 28, 2026
Critical CVE-2023-38408 in libcue Exposes Linux, Windows, macOS Users to Tracking
September 28, 2026
NCSC Urges UK organizations to Patch for Citrix NetScaler ADC and Gateway 0-Day Vulnerabilities
September 28, 2026
Home/CyberSecurity News/Bitget Suffers $387.5M Loss in Backend Breach, DPRK-Linked Launderers Implicated
CyberSecurity News

Bitget Suffers $387.5M Loss in Backend Breach, DPRK-Linked Launderers Implicated

Key Takeaways Cryptocurrency exchange Bitget suffered a significant backend breach, resulting in a loss of approximately $387.5 million. The attack exploited a critical backend component, enabling...

David kimber
David kimber
September 28, 2026 4 Min Read
2 0

Key Takeaways

  • Cryptocurrency exchange Bitget suffered a significant backend breach, resulting in a loss of approximately $387.5 million.
  • The attack exploited a critical backend component, enabling fraudulent transaction authorizations without compromising private keys.
  • North Korean-linked threat actors are suspected, with their money launderers exhibiting notable operational security failures.
  • Bitget’s cold wallets and self-custodial services were unaffected; customer funds are covered by a protection fund.
  • Withdrawals are being progressively restored, and the vulnerability has been patched.

Cryptocurrency exchange Bitget has commenced the phased restoration of withdrawal services following a sophisticated backend breach on September 24. Attackers exploited the platform’s wallet infrastructure, siphoning approximately $387.5 million from its hot and warm crypto holdings.

Table Of Content

  • Key Takeaways
  • Bitget Backend Breach Details
  • Launderers Expose Themselves
  • What You Should Do

Bitget confirmed that the incident did not involve the theft of private keys. Furthermore, its offline cold storage wallets and the separate, self-custodial Bitget Wallet service remained secure and untouched by the breach.

This incident underscores a critical vulnerability in the cryptocurrency ecosystem: even robust key protection mechanisms can be circumvented if the backend systems responsible for preparing, validating, and authorizing blockchain transactions are compromised.

The exchange first detected unauthorized transfers at 18:31 UTC and promptly initiated emergency response protocols, leading to the immediate suspension of all withdrawals. Bitget CEO Gracy Chen stated that the intruders managed to compromise a crucial backend component, allowing them to spoof transaction data and trick the platform’s authorization process into approving illicit transfers.

Bitget Backend Breach Details

Initially, Bitget estimated losses at $351.6 million. However, this figure was later revised upwards after further tracing of Zcash and TRON transactions. The stolen assets encompassed a variety of cryptocurrencies, including XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX, and TRX.

XRP constituted the largest identified portion of the theft, with on-chain analysis pinpointing approximately 102.93 million XRP, valued at around $157.5 million. Additionally, 31,890 ETH, worth roughly $85.75 million, was stolen. A substantial amount of the illicitly obtained funds was subsequently converted, bridged across different networks, or redistributed, creating a complex and rapidly shifting trail for investigators to follow.

Launderers Expose Themselves

In a striking development, blockchain investigator ZachXBT uncovered significant operational security lapses among individuals allegedly laundering the stolen proceeds on behalf of the suspected North Korean attackers.

ZachXBT’s findings indicate that Chinese illicit actors, operating under five distinct aliases, openly sought technical support in public Discord servers and Telegram channels when their attempts to swap stolen assets encountered issues. As ZachXBT revealed on September 28, 2026: “BREAKING: Chinese illicit actors laundering funds from the $387M Bitget exploit on behalf of the alleged DPRK attackers are openly asking for support with orders in public Discord servers and Telegram channels of services they use. Notably, Alias 4 (below) was also seen… pic.twitter.com/KfdTo51M2o“

Screenshots provided by ZachXBT illustrate these users inquiring about delays in large XRP-to-BTC orders, even publishing transaction identifiers and directly tagging service operators. This effectively exposed their money laundering activities while they sought assistance for their stalled transactions.

The aliases identified in ZachXBT’s transaction map include “jack,” “HELP ME,” “Melon,” “Cc,” and “lolo/Marin.” One account reportedly lamented sending 277,724 XRP but receiving only 431 XRP back after a duplicate transaction was refunded.

The map links these individuals through intermediary wallets connected to the Bitget theft and tracks fund flows towards THORChain. ZachXBT further noted that Alias 4, identified as lolo or Marin, had previously been involved in laundering funds from the $292 million Kelp DAO exploit earlier in 2026.

Investigators have observed the stolen funds moving through various obfuscation techniques, including cross-chain bridges, asset swaps, and privacy tools. AMLBot traced one specific path from TRX to USDT, then across USDT0 to Ethereum, converting into approximately 145 ETH, subsequently moving through THORChain, and finally ending up as about 4.59 BTC.

Around four BTC from this chain then entered a Wasabi CoinJoin round, a privacy-enhancing technique where transactions from multiple participants are combined to complicate forensic attribution.

Bitget has confidently attributed the attack to a North Korean-linked group, citing specific IP behavior and on-chain signatures. However, no independent authority has yet publicly confirmed this definitive attribution. Mandiant and SlowMist are actively assisting with the ongoing investigation, and law enforcement agencies have been notified. Bitget has affirmed that its protection fund will cover the financial impact, ensuring that customer balances remain secure and intact.

Withdrawal services are being progressively reinstated, starting with Bitcoin on September 28, followed by Ethereum on September 29, USDT on September 30, and other tokens, fiat, and peer-to-peer services on October 2.

The exchange confirmed that the exploited vulnerability has been fully remediated, preventing any further unauthorized transfers, while investigators continue their efforts to trace and freeze the stolen assets.

What You Should Do

  • If you are a Bitget user, monitor official Bitget communications for updates on withdrawal restoration and any security advisories.
  • Enable Two-Factor Authentication (2FA) on all cryptocurrency exchange accounts and financial services.
  • Be vigilant against phishing attempts that may leverage news of the breach. Always verify the authenticity of communications from Bitget.
  • Consider diversifying your cryptocurrency holdings across multiple reputable exchanges and secure hardware wallets to mitigate risk.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitSecurityVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

OpenCode AI Coding Agent Flaw Lets Malicious Websites Execute Code

Next Post

NCSC Urges UK organizations to Patch for Citrix NetScaler ADC and Gateway 0-Day Vulnerabilities

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
ShinyHunters Exploits Critical Oracle PeopleSoft CVE-2024-21095 to Deploy Web Shells
September 28, 2026
Attackers Intercept AI Prompts via Fake Jev AI Stores
September 28, 2026
NVIDIA Unveils Open Safety Platform for Autonomous AI Agents With 100 Partners
September 28, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us