Full Report
Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million. [...]
Analysis Summary
# Incident Report: Bitget Wallet Infrastructure Breach
## Executive Summary
In September 2026, the cryptocurrency exchange Bitget suffered a major security breach resulting in the theft of approximately $387.5 million in various digital assets. Suspected North Korean state-sponsored hackers compromised a critical backend system to spoof transaction data, tricking the exchange’s authorization mechanisms into transferring funds from hot and warm wallets. Bitget has since contained the incident, resumed Bitcoin withdrawals, and utilized its Protection Fund to cover user losses.
## Incident Details
- **Discovery Date:** September 24, 2026 (Thursday)
- **Incident Date:** Week of September 21, 2026
- **Affected Organization:** Bitget
- **Sector:** Financial Services / Cryptocurrency Exchange
- **Geography:** Global
## Timeline of Events
### Initial Access
- **Date/Time:** Preceding September 24, 2026
- **Vector:** Exploitation of a vulnerability in a critical backend system.
- **Details:** Attackers gained access to Bitget’s internal wallet infrastructure.
### Lateral Movement
- **Details:** Attackers moved from the initial entry point to the transaction authorization layer of the wallet infrastructure.
### Data Exfiltration/Impact
- **Details:** Attackers spoofed transaction data to authorize withdrawals across multiple chains (Ethereum, XRP, Arbitrum, Avalanche, Optimism, BSC, and Base). A total of $387.5 million in assets, including ETH, XRP, BNB, AVAX, USDT, and USDC, were transferred to attacker-controlled addresses.
### Detection & Response
- **Discovery:** Security systems flagged multiple unauthorized transfers from a limited number of wallets on Thursday, September 24.
- **Response actions taken:** Immediate suspension of all withdrawals; identification of the exploited vulnerability; deployment of security patches; activation of the "Protection Fund" to cover losses.
## Attack Methodology
- **Initial Access:** Exploitation of a security vulnerability in a backend system.
- **Persistence:** Not explicitly disclosed, but involved maintained access to internal infrastructure.
- **Privilege Escalation:** Gaining unauthorized control over the transaction authorization process.
- **Defense Evasion:** Use of spoofed transaction data to mimic legitimate withdrawal requests.
- **Credential Access:** Breach of wallet infrastructure backend.
- **Discovery:** On-chain tracing and IP behavior analysis (later used by Bitget to attribute the attack to North Korean actors).
- **Lateral Movement:** Pivot from backend systems to wallet management layers.
- **Collection:** Aggregation of funds from hot and warm wallets.
- **Exfiltration:** Unauthorized transfers to external blockchain addresses.
- **Impact:** Financial theft and temporary suspension of platform services.
## Impact Assessment
- **Financial:** $387.5 million stolen. (Bitget’s "Protection Fund" used to mitigate user impact).
- **Data Breach:** Spoofed transaction data; no reports of personal user data (PII) theft.
- **Operational:** Platform-wide suspension of withdrawals for over a week; phased resumption of services.
- **Reputational:** High-profile breach attributed to state-sponsored actors; requires restoration of user trust through the Recovery Bounty Program.
## Indicators of Compromise
- **Network indicators:** IP behavior patterns associated with North Korean threat groups (specific IPs not disclosed in the article).
- **Behavioral indicators:** Abnormal volume of unauthorized transfers; spoofed transaction metadata triggering automated authorization.
- **On-chain indicators:** Attacker-controlled addresses visible via `trace.bgblockchain[.]xyz/v2#explorer`.
## Response Actions
- **Containment:** Suspended all withdrawal services to prevent further fund outflow.
- **Eradication:** Addressed and patched the backend vulnerability in the wallet infrastructure.
- **Recovery:** Phased resumption of withdrawals (BTC on Sept 28; ETH/Layer 2s on Sept 29; USDT on Sept 30); launched a 5% Recovery Bounty Program for fund recovery.
## Lessons Learned
- **Backend Vulnerabilities:** Critical backend systems managing wallet authorizations represent a single point of failure that requires rigorous isolation.
- **Automated Authorization Risks:** Attackers can bypass security by spoofing the data that triggers automated "green-lights" for transfers.
- **Hot/Warm Wallet Exposure:** Large balances in hot and warm wallets remain high-priority targets for sophisticated state-sponsored actors.
## Recommendations
- **Multi-Party Computation (MPC):** Implement or strengthen MPC for transaction signing to ensure no single backend system compromise can authorize a transfer.
- **Anomaly Detection:** Enhance real-time monitoring to flag and auto-block transfers that deviate from historical volume or frequency patterns, even if "authorized."
- **Cold Storage Migration:** Shift a higher percentage of assets to air-gapped cold storage to reduce the potential "blast radius" of a hot wallet breach.
- **External Audits:** Conduct frequent, deep-dive audits of the backend code governing wallet-to-blockchain interactions.