Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Your LG TV is constantly collecting your data – here’s how to stop it

    September 25, 2026

    The SOC Doesn’t Need to Start Over with Every Alert

    September 25, 2026

    SlowMist Has Yet to Confirm Crypto Theft From iPhone Safari Attack

    September 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Your LG TV is constantly collecting your data – here’s how to stop it
    • The SOC Doesn’t Need to Start Over with Every Alert
    • SlowMist Has Yet to Confirm Crypto Theft From iPhone Safari Attack
    • CNOOC keeping Worley busy on its North Sea assets for five more years
    • Ethiopia war: Internet disrupted in Tigray
    • Burnham plans first Berlin visit for talks with Merz – POLITICO
    • Nexterity wants to automate the hard, dangerous part of pipefitting
    • Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 25, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 25, 2026Cryptocurrency / Cybercrime

    Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.

    “At 18:31 UTC on September 24, 2026, Bitget’s security systems identified unauthorized transfers involving a limited number of hot wallets,” BitGet said in a post shared on X. “Bitget’s cold wallets and the overwhelming majority of platform assets remain secure and unaffected.”

    The company emphasized that customer account balances remain accurate, and deposits and trading continue to operate normally. However, withdrawals have been temporarily suspended out of an abundance of caution while a “comprehensive security review” is underway.

    Bitget did not disclose any details on how the attack took place, but said it has enlisted the help of Google-owned Mandiant and SlowMist for a third-party investigation.

    “Bitget Wallet operates as a self-custodial wallet on a completely separate and independent infrastructure from Bitget Exchange and was not affected by this incident,” it noted.

    Cybersecurity

    According to Bitget CEO Gracy Chen, assets impacted by the hack include ETH, XRP, BNB, AVAX, USDT, and USDC, with the chains involving Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base.

    “We have contacted the foundations of all affected chains, and some foundations have confirmed the freezing of hacker wallet addresses,” Chen said. “Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations.”

    “The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation.”

    The development comes about a week after SentinelOne attributed the North Korea-linked TraderTraitor group to an attack targeting an India-based information technology (IT) services company. TraderTraitor is best known for the theft of $1.5 billion from Bybit and $292 million from KelpDAO’s LayerZero bridge.

    351.6M Backend Bitget compromise hackers Korean North stole Suspected
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    The SOC Doesn’t Need to Start Over with Every Alert

    CNOOC keeping Worley busy on its North Sea assets for five more years

    Microsoft: Recent Windows updates cause desktop loading issues

    Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

    Bitget’s North Korea-linked $352 million hack could drain 76% of its protection fund

    FBI investigating claim hackers have stolen details of all its agents

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Your LG TV is constantly collecting your data – here’s how to stop it

    September 25, 2026

    The SOC Doesn’t Need to Start Over with Every Alert

    September 25, 2026

    SlowMist Has Yet to Confirm Crypto Theft From iPhone Safari Attack

    September 25, 2026

    CNOOC keeping Worley busy on its North Sea assets for five more years

    September 25, 2026
    Latest Posts

    A Growing Number of Election Deniers Hold Key Local Roles in Midterms

    August 6, 2026

    Lithuania warns Russia could be considering possible ‘false flag’ strike on the Baltics – Europe live | Europe

    August 6, 2026

    Will Mamdani’s city-run grocery stores require ID to shop? Here’s the truth

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Your LG TV is constantly collecting your data – here’s how to stop it

    September 25, 2026

    The SOC Doesn’t Need to Start Over with Every Alert

    September 25, 2026

    SlowMist Has Yet to Confirm Crypto Theft From iPhone Safari Attack

    September 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.