Bitget Hack Explained: How $387 Million Vanished Without a Stolen Private Key
On September 24, 2026, suspected North Korean hackers drained $387.5 million from crypto exchange Bitget's hot wallets — not by stealing keys, but by spoofing its own approval system. Here's what happened, how Bitget is covering it, and what it means for your crypto.
▶ View as web storyOn September 24, 2026, crypto exchange Bitget disclosed that attackers had drained crypto from its hot and warm wallets, with the confirmed loss revised upward to about $387.5 million the next day — the largest crypto exchange hack of 2026 so far. Unusually, Bitget says no private keys were stolen; instead, attackers reportedly spoofed the exchange’s own backend systems into approving withdrawals that were never legitimate.
What actually happened, and when
Bitget first went public on September 24 with an estimate of roughly $351.6 million in losses and immediately paused withdrawals (CoinDesk, Bloomberg). As the exchange’s investigation continued, it found additional affected assets on networks including TRON and Zcash that weren’t captured in the first count, and on September 25 raised the confirmed total to about $387.5 million across seven blockchain networks (Fortune). Assets taken included XRP, ETH, and various stablecoins, drained from wallets Bitget uses to process everyday customer trades and withdrawals.
That makes it the biggest single crypto hack of the year, surpassing the roughly $319 million taken from Blockstream’s Liquid Network earlier in 2026, though still well behind the record-setting $1.4–1.5 billion stolen from Bybit in February 2025 — the largest crypto theft in history.
How the hackers pulled it off
What makes this hack unusual isn’t the size — it’s the method. According to Bitget CEO Gracy Chen, speaking during a livestream after the breach, the attacker “compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out” (CoinDesk).
In plain English: the attackers didn’t steal the digital keys that control Bitget’s wallets, the way hackers usually do. Instead, they found a way to fake the internal paperwork the exchange’s own systems rely on to decide a withdrawal request is real — and Bitget’s automated approval process signed off on transfers it should have rejected. No key theft, no obvious external red flag until the money was already gone.
Why hot wallets fell but cold wallets didn’t
Every major exchange splits customer funds across different types of storage, and this hack is a good illustration of why that matters:
- Hot wallets stay connected to the internet so an exchange can process withdrawals instantly. They’re convenient — and the most exposed.
- Warm wallets sit in between, used for slightly less frequent but still relatively fast transfers.
- Cold wallets are kept fully offline, usually requiring physical access or multiple independent approvals to move funds. They’re slow to use by design, which is exactly what makes them hard to hack remotely.
Bitget says the breach was contained to its hot and warm wallets; its offline cold storage, which holds the bulk of customer assets, was never touched (TRM Labs). That’s the same architecture that limited (but didn’t prevent) damage in past exchange hacks — the tradeoff between convenience and security is structural, not a one-off failure.
The North Korea connection
Blockchain analytics firm TRM Labs traced the stolen funds through a laundering pattern it says is consistent with prior North Korea–linked operations: funds on BNB Chain and Ethereum were swapped through the cross-chain protocol THORChain and split into Bitcoin “peel chains” (a technique of repeatedly moving small amounts through new addresses to obscure the trail), while stolen TRX on TRON was swapped for USDT and routed through the same THORChain path (TRM Labs). Combined with IP addresses and wallet-reuse patterns from earlier incidents, this led Bitget and multiple investigators to suspect North Korea’s Lazarus Group, tracked by security researchers under the cluster name TraderTraitor (Fortune).
This fits a well-documented pattern. The FBI formally attributed the record $1.5 billion Bybit theft in February 2025 to the same TraderTraitor cluster. TRM Labs estimates DPRK-linked actors stole $2.02 billion across all of 2025 — a 51% jump from the year before — pushing their all-time cumulative haul to roughly $6.75 billion (TRM Labs). Earlier in 2026, North Korea-linked hackers were already responsible for an estimated 76% of all crypto hack losses for the year through April, driven mainly by two attacks — the $285 million Drift Protocol breach and the $292 million KelpDAO bridge exploit — before the Bitget hack added to the tally.
Bitget vs. Bybit: two very different hacks
| Bitget (September 2026) | Bybit (February 2025) | |
|---|---|---|
| Amount stolen | ~$387.5 million | ~$1.4–1.5 billion |
| Wallets hit | Hot and warm only; cold wallets untouched | Cold wallet, compromised mid-transfer |
| Attack method | Backend system allegedly spoofed to fake withdrawal authorization | Attackers reportedly manipulated a signer’s interface during a scheduled multisig transfer |
| Private keys stolen? | No, per Bitget | No, signers were tricked into approving a malicious transaction |
| Suspected attribution | North Korea (Lazarus / TraderTraitor) — not yet formally confirmed | North Korea (Lazarus / TraderTraitor) — confirmed by the FBI |
| Recovery plan | Covered by Bitget’s ~$464M User Protection Fund | Covered via Bybit’s own reserves and bridge financing |
How Bitget is making users whole
Bitget says every dollar of the confirmed loss will be covered by its User Protection Fund, a reserve first established in 2022 with an initial $300 million commitment. The fund currently holds about 5,500 BTC, worth roughly $464 million at the time of the hack — enough to absorb the $387.5 million loss with room to spare, according to reporting on the fund’s holdings (PANews). Bitget has also offered separate 5% bounties for information leading to the freezing of stolen funds and for their recovery.
Withdrawals are returning in stages rather than all at once: Bitcoin withdrawals resumed first on September 28, with Ethereum following on September 29 and Tether (USDT) on September 30, and the exchange targeting a full return to normal service by October 2 (Infosecurity Magazine).
What this means if you keep crypto on an exchange
A hack like this is a reminder that “the exchange got hacked” doesn’t always mean what people assume. It doesn’t have to involve a stolen password or a leaked private key — it can be a flaw in the internal software an exchange trusts to approve its own transactions, which is arguably harder for an outsider to predict or defend against. That’s also exactly the kind of headline-driven event that can rattle short-term sentiment across the market, something we cover in more depth in what actually moves Bitcoin’s price.
A few practical takeaways:
- A protection fund is not a guarantee. Bitget’s fund happened to be large enough this time. Funds are finite, and a bigger or better-timed hack could exceed them.
- Cold storage isn’t marketing — it’s the actual reason cold wallets survived. If you’re holding crypto long-term rather than actively trading it, a hardware wallet you control removes exchange risk entirely.
- Diversifying where you keep funds matters, the same way you wouldn’t keep all your cash at one bank branch with no backup plan.
- “No private keys were stolen” isn’t automatically reassuring. It just means the attack surface has moved to internal software and authorization logic — which every exchange, not just Bitget, has to keep defending.
The takeaway
Bitget’s $387.5 million hack is the largest crypto exchange breach of 2026, notable less for its size than for how it happened: a spoofed backend authorization process rather than a stolen key. Bitget’s Protection Fund appears able to cover the loss and withdrawals are being restored in stages, but the underlying lesson holds regardless of how this particular story ends — exchange convenience and exchange risk are two sides of the same coin, and the safest crypto is usually the crypto you don’t leave sitting on someone else’s hot wallet.
This is education, not financial advice. Crypto exchanges carry real custodial and security risk regardless of their size or reputation — do your own research, and consider self-custody for funds you don’t need immediate trading access to.