Full Report
Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. [...]
Analysis Summary
# Incident Report: Bitget Wallet Infrastructure Compromise
## Executive Summary
Bitget cryptocurrency exchange suffered a major security breach resulting in the theft of $351.6 million from its hot and warm wallets. Attributed to suspected North Korean threat actors, the attackers compromised a critical backend wallet-service system to forge transaction data and bypass authorization controls. Bitget has committed to covering all losses via its $464 million User Protection Fund, ensuring no financial loss for users.
## Incident Details
- **Discovery Date:** Thursday evening, September 24, 2026 (based on disclosure date)
- **Incident Date:** September 24-25, 2026
- **Affected Organization:** Bitget
- **Sector:** Financial Services (Cryptocurrency Exchange)
- **Geography:** Global
## Timeline of Events
### Initial Access
- **Date/Time:** September 24, 2026
- **Vector:** Intrusion into critical backend wallet-service infrastructure.
- **Details:** Attackers gained access to the system responsible for managing wallet services and transaction signing.
### Lateral Movement
- **Details:** The attackers moved from the initial entry point to the backend system capable of interacting with the authorization-signing process for multiple blockchain networks.
### Data Exfiltration/Impact
- **Details:** $351.6 million in assets stolen across Ethereum, XRP Ledger (largest single-chain loss), Arbitrum, Avalanche, Optimism, BSC, and Base. Assets included ETH, XRP, BNB, AVAX, USDT, and USDC.
### Detection & Response
- **Discovery:** Flagged by internal security systems monitoring for multiple unauthorized transfers.
- **Response actions taken:** Immediate suspension of withdrawals; engagement with Mandiant, SlowMist, and law enforcement; freezing of known hacker addresses on specific chains.
## Attack Methodology
- **Initial Access:** System intrusion into backend wallet-service infrastructure (specific entry vector under investigation).
- **Persistence:** Not explicitly disclosed; likely maintained via compromised service accounts.
- **Privilege Escalation:** Gained sufficient rights to interact with the internal transaction authorization-signing process.
- **Defense Evasion:** Used IP behavior patterns consistent with state-sponsored activity to mask origin.
- **Credential Access:** Compromised internal system credentials or API keys used for wallet management.
- **Discovery:** Targeted specific hot and warm wallet backend services.
- **Lateral Movement:** Focused movement between infrastructure servers and signing modules.
- **Collection:** Forged transfer information to simulate legitimate transaction requests.
- **Exfiltration:** Assets transferred to attacker-controlled addresses across multiple chains.
- **Impact:** Theft of $351.6 million in digital assets.
## Impact Assessment
- **Financial:** $351.6 million loss (covered by the internal User Protection Fund).
- **Data Breach:** Compromise of internal transaction signing logic and backend system integrity.
- **Operational:** Temporary suspension of all platform withdrawals; intense forensic investigation.
- **Reputational:** Significant public disclosure of a high-value hack linked to North Korean state-sponsored actors.
## Indicators of Compromise
- **Network indicators:** IP behavior patterns consistent with North Korean hacking groups (specific IPs not disclosed in the report).
- **File indicators:** Not disclosed; pending forensic report from Mandiant/SlowMist.
- **Behavioral indicators:** Rapid, unauthorized outbound transfers from hot/warm wallets; spoofed transaction data originating from internal backend systems.
## Response Actions
- **Containment:** Suspended all cryptocurrency withdrawals to prevent further drainage.
- **Eradication:** Isolated the compromised backend system and revoked unauthorized access.
- **Recovery:** Activation of the $464 million User Protection Fund to reimburse affected users; phased restoration of withdrawals following security audit.
## Lessons Learned
- **System Segregation:** While Bitget's cold wallets and self-custodial "Bitget Wallet" remained safe due to infrastructure independence, the hot/warm wallet backend proved a single point of failure.
- **Signing Logic Security:** Attackers were able to "spoof" transaction data that the authorization process accepted as valid, suggesting a need for more robust multi-party computation (MPC) or hardware-based signing for hot wallets.
## Recommendations
- **Zero Trust Architecture:** Implement stricter micro-segmentation around the wallet-service backend to limit the impact of a system intrusion.
- **Enhanced Transaction Monitoring:** Integrate real-time behavioral alerts for unusual transaction volumes or frequencies at the signing level.
- **Multi-Signature Requirements:** Ensure that hot/warm wallet transfers require multi-factor authorization that cannot be bypassed even if a single backend system is compromised.