Bitget CEO Gracy Chen stated that North Korea is “very likely” responsible for the $350 million breach suffered by the exchange. She added that the culprits compromised a backend system without ever acquiring private keys.
Following the September 24 security breach, withdrawals continue to be paused. According to figures from DefiLlama, the event currently stands as the biggest cryptocurrency hack of 2026.
Chen Follows a VPN Trail to North Korea
During an X live Q&A session held in the wake of the event, Chen discussed the security breach and pointed toward the Democratic People’s Republic of Korea (DPRK).
“But we’ve identified some IP addresses that match the VPN choices by a certain DPRK group. So we think this is very likely to be attacked by North Korean,” she said.
Although Chen refrained from naming a specific collective, on-chain investigator Specter pointed out that the stolen XRP has been bridged and connects directly to funds taken in the AFX Trade exploit.
The AFX incident resulted in a loss of roughly $24 million back in July, which Specter tied to TraderTraitor, a unit linked to the Lazarus Group. LayerZero previously connected the KelpDAO bridge exploit to this same unit in April.
How the Bitget Hack Bypassed Private Keys
According to Chen, the hackers never gained access to private keys for Bitget’s hot, warm, or cold storage wallets, nor did they forge user withdrawal requests. She elaborated further on the execution method in a subsequent post.
“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” she explained.
She noted that the situation is contained and further unauthorized fund movements are blocked. Data from Lookonchain indicates the perpetrators made off with 9 distinct assets.
XRP accounted for the largest portion, with roughly 102.9 million tokens valued at approximately $157.5 million. Bitget’s verified losses are about double the initial on-chain estimates of roughly $176 million.
The exchange reports that its User Protection Fund stands above $464 million and is sufficient to absorb the entire loss.
The Biggest Crypto Heist of 2026 Lands at Bitget
DefiLlama metrics categorize the Bitget breach as the premier cryptocurrency theft of 2026 to date, surpassing the $320 million Liquid Network attack in September and the $295 million Drift breach in April.
The tracking platform records roughly $2.2 billion lost across 281 separate events this year, with Bitget alone representing about 16% of the aggregate sum. Consequently, September has become the costliest month of 2026 so far, exceeding April’s approximate total of $648 million.
North Korean threat actors have been responsible for the majority of early 2026 losses. Research by TRM Labs revealed they made up 76% of crypto hack losses through April, driven largely by the Drift and Kelp incidents. Previously, in 2025, the Lazarus Group executed the $1.5 billion Bybit exploit, marking the top theft of that year.
Chen has committed to publishing a comprehensive technical report once investigators finalize their analysis of how the breach occurred. That documentation is expected to clarify whether forensic evidence supports the North Korean attribution.
Subscribe to our YouTube channel to watch leaders and journalists provide expert insights
Frequently Asked Questions
-
How much was stolen in the Bitget hack?
Bitget confirmed losses of approximately $350 million, making it the largest crypto hack of 2026 according to DefiLlama data. -
Who is suspected of carrying out the attack?
Bitget CEO Gracy Chen stated it is “very likely” North Korean actors were behind the breach, citing matching VPN IP addresses. On-chain analysts also linked the stolen XRP to the Lazarus-linked unit TraderTraitor. -
Did the hackers obtain private keys?
No. According to CEO Gracy Chen, the attackers did not obtain private keys or forge user withdrawal requests; instead, they compromised a critical backend system to spoof transaction data. -
Are user funds safe?
Bitget stated that losses are contained and that its User Protection Fund, which holds over $464 million, will cover the full loss. Withdrawals remain suspended following the September 24 breach.


