Bitget Loses $351.6M in Largest 2026 Crypto Wallet Hack

Bitget Loses $351.6M in Largest 2026 Crypto Wallet Hack

On September 24, 2026, unauthorised transfers drained an estimated USD 351.6 million from Bitget's hot and warm wallets spanning Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain and Base. The exchange identified the outflows at 18:31 UTC, suspended withdrawals and stated that its User Protection Fund holds sufficient reserves to cover the shortfall. By value, this is the largest digital-asset theft recorded in 2026.

Five core findings

  • An estimated USD 351.6 million left Bitget's hot and warm wallets on September 24, 2026. According to the exchange, attackers penetrated a backend system, altered transaction information presented to the approval logic and induced the platform to authorise the outbound transfers. Bitget maintains that no private keys were exfiltrated.
  • Initial public estimates ranged between USD 170 million and USD 190 million because they captured only EVM-compatible chains. TRM data records approximately USD 158 million departing via the XRP Ledger, reconciling observed flows with Bitget's declared loss.
  • Stolen ETH and XRP moved rapidly into fresh wallets, many holding standardised sums near 10,000 ETH or 20 million XRP. As of the morning of September 25, the majority of those balances remained stationary.
  • Bitget halted withdrawals and confirmed that its USD 464 million User Protection Fund will absorb the loss. Cold-storage wallets were not breached.
  • Bitget's chief executive described North Korean involvement as "very likely." TRM has identified multiple on-chain intersections with wallets previously tied to North Korean operations—including Bybit and AFX Bridge—that route through a laundering infrastructure TRM has not seen serve any other actor. Definitive attribution has not yet been published, and the possibility of a different perpetrator remains open.

Mechanism of the breach

Hot and warm wallets enable exchanges to process customer withdrawals while the bulk of assets stay offline. Even so, every transfer requires authorisation before signature. Gracy Chen, Bitget's chief executive, stated that an intruder accessed a backend system linked to the wallet infrastructure, falsified the transaction details fed into the approval workflow and caused the platform to sign the transfers. The exchange asserts that private keys remained secure and that cold wallets saw no unauthorised activity.

The compromise shares a structural similarity with the February 2025 Bybit incident: the attacker altered the information presented to the authorisation layer. In Bybit's case, that manipulation persuaded signers to release funds from a cold wallet; at Bitget, it tricked the withdrawal controls into greenlighting hot- and warm-wallet outflows. Neither scenario relies on stolen keys.

Because early on-chain tallies focused on Ethereum and other EVM chains, they settled on a figure between USD 170 million and USD 190 million. Bitget declared a loss of USD 351.6 million. TRM data records roughly USD 158 million in XRP and USD 7 million in TRX also exiting Bitget wallets, aligning observed outflows with the exchange's total.

Rapid redistribution into standardised holding wallets

On Ethereum, a large portion of the stolen value transited through 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee, which also collected funds on Arbitrum, Avalanche, Base, BNB Chain and Optimism. A second address, 0xa6dd3f218b65e32ccc37be30f74884133c655545, dispersed its holdings to newly generated wallets over approximately two hours on the evening of September 24. Most recipients held close to 10,000 ETH. Combined with wallets funded directly from the first address, eight wallets absorbed the majority of the stolen ETH. None had initiated further transactions by the morning of September 25.

XRP followed a parallel pattern. Funds departing Bitget passed through smaller relay accounts before landing in discrete wallets holding round sums of 20 million XRP. The bulk of that XRP also sat idle as of the morning of September 25.

A fraction of the proceeds had started converting into Bitcoin. Assets on BNB Chain and Ethereum were exchanged via THORChain and distributed across Bitcoin addresses in peel-chain sequences. On TRON, stolen TRX was swapped for USDT on SunSwap, bridged to Ethereum through USDT0 and funnelled into the same THORChain route. Smaller volumes moved through Across, Bridgers, Chainflip and FixedFloat.

TRM Forensics has labelled exploiter addresses under the cluster designation "Bitget Exploiter September 2026." Tags have propagated from Ethereum to additional chains—including the XRP Ledger and Bitcoin—and now encompass intermediate wallets downstream in the fund flow.

One documented path traces BNB from a Bitget hot wallet to THORChain. Approximately USD 9.8 million in BNB departed Bitget on the evening of September 24 and moved through several exploiter wallets before being subdivided. Over the following thirteen hours, portions reached THORChain in increments of a few hundred thousand USD each and were converted to Bitcoin.

Evidence cited for North Korean involvement

Gracy Chen stated that North Korean participation is "very likely," pointing to IP addresses that Bitget's preliminary investigation connected to VPN services linked to a North Korean hacking collective. The attack method—manipulating approval data rather than extracting private keys—mirrors the February 2025 Bybit theft, which the FBI attributed to North Korea.

On-chain tracing has uncovered several overlaps with wallets used to launder earlier North Korean thefts, notably Bybit and AFX Bridge. At minimum, these intersections confirm that the entity laundering the Bitget proceeds is the same syndicate employed by TraderTraitor in other recent operations. TRM has not observed this laundering network handle proceeds for any other hacking group; the overlaps therefore point toward TraderTraitor. TRM anticipates that firmer technical evidence will surface in coming days.

The laundering pattern matches recent North Korean heists. Within hours, the funds were divided into fresh wallets holding standardised amounts, most of which then remained static. The portion that has moved passed through swap services—including THORChain—into ETH and BTC. Those services and techniques are accessible to other threat actors as well.

Should the Bitget theft be attributed to North Korea, 2026 would rank as the second-largest year for North Korean crypto theft in TRM's dataset, exceeding USD 1 billion and trailing only 2025. Hacks attributed to North Korea total approximately USD 690 million in 2026 to date, predominantly from the Drift Protocol and KelpDAO attacks.

Outstanding questions and next steps

The funds that have not yet moved represent the principal unknown. As of the morning of September 25, most stolen ETH and XRP remained in the holding wallets described above. Following the Bybit theft, a substantial portion of converted bitcoin stayed largely dormant before entering the next laundering phase through mixers and over-the-counter networks, and Drift proceeds similarly sat idle in newly created wallets after the attack.

When the Bitget funds do move, the route established so far indicates where they are likely to reappear. Proceeds routed through bridges, cross-chain swap services and Bitcoin peel chains typically reach exchanges several hops removed from a tagged address rather than directly, so linking those deposits to the exploit requires tracing across multiple hops and chains. Exchanges and virtual asset service providers should screen incoming deposits not only against the tagged Bitget exploiter addresses but also against funds several steps downstream, because proceeds are more likely to arrive indirectly. Members of the Beacon Network receive exploiter addresses as they are identified.

Attribution remains the other open question. Bitget has promised an incident report that may clarify how the backend system was compromised and whether the evidence supports a North Korean link. TRM is monitoring the tagged addresses and will update this analysis as attribution and fund flows develop.

Source: www.trmlabs.com

Free First Assessment

Let's recover your funds.

  • Free case analysis — no commitment
  • Analyst reply in under 10 min
  • NDA by default

Your contact details *