Crypto theft has become one of the biggest security challenges facing the digital asset industry, with hackers and state-linked groups targeting crypto platforms, wallets, and other blockchain infrastructure for billions of dollars.
Among the most persistent actors is North Korea, whose cyber operations have increasingly focused on stealing digital assets to generate revenue.
North Korean-linked hackers have now stolen more than $1 billion in cryptocurrency in 2026, with the latest figure highlighting the growing scale and sophistication of attacks targeting the crypto industry.
Register for the next Tekedia Mini-MBA.
Register for Tekedia AI in Business Masterclass.
Join Tekedia Capital Syndicate and co-invest in great global startups.
The tally was pushed higher following a major attack on Bitget, adding to a series of high-value crypto thefts attributed to North Korean cyber actors this year
On September 24, 2026, attackers executed unauthorized transfers from Bitget’s hot and warm wallets, with the exchange detecting the activity around 18:31 UTC.
Initial estimates put the loss at approximately $351.6 million, later revised upward to $387.5 million after additional assets on networks including Zcash and TRON were identified.
The haul included significant amounts of XRP (roughly 103 million tokens valued near $157 million), ether, USDT, USDC, BNB, AVAX, and other tokens moved across Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain, Base, and additional networks.
Bitget CEO Gracy Chen stated that the attackers did not steal private keys. Instead, they compromised a critical backend system within the wallet infrastructure, spoofed or forged transaction data, and triggered the platform’s own authorization process to move funds.
She wrote on X,
“The security team has initially identified the source of the attack. Hackers breached a key backend system of the wallet service and exploited it to forge transfer information and invoke the authorization signing process, thereby transferring funds out. The possibility of private key leakage can be ruled out, this means a more severe risk scenario has been eliminated.
“Damage control has been confirmed as complete, and there is no risk of further fund outflows from the platform. The specific intrusion methods used by the hackers are still under technical investigation, and a full report will be released upon completion of the investigation.”
Cold wallets remained unaffected, and the company quickly contained further outflows. Withdrawals were suspended while deposits and trading continued.
Bitget’s User Protection Fund, holding more than $464 million, fully covers the losses, and the exchange has pledged to restore customer access once security reviews are complete.
Independent investigators including Mandiant and SlowMist were brought in, and Bitget is cooperating with law enforcement and relevant blockchain teams, some of which have already frozen linked addresses.
Chen described the attack as highly consistent with known patterns of North Korean hacker organizations, citing IP behavior, VPN usage matching previous DPRK-linked activity, and on-chain signatures.
Blockchain analytics firm Elliptic assessed the incident as highly likely linked to the Democratic People’s Republic of Korea, noting similarities in fund movement and laundering techniques, as well as connections to addresses tied to earlier operations such as the $1.5 billion Bybit exploit in 2025.
The Bitget breach ranks as the largest single crypto theft of 2026 to date and elevates Elliptic’s tracked total of suspected North Korean crypto heists for the year above $1 billion.
North Korean state-sponsored groups, often associated with the Lazarus Group and related clusters, have dominated large-scale crypto crime in recent years.
They accounted for a substantial share, frequently cited in the range of half to three-quarters of stolen value in 2026 prior to this incident, building on a 2025 total near $2 billion and a cumulative haul exceeding $6 billion since the mid-2010s.
Security firms and governments have long linked these operations to funding for North Korea’s weapons programs. The attackers’ typical approach emphasizes social engineering, infrastructure compromises, and sophisticated cross-chain laundering rather than pure smart-contract exploits.
The Bitget incident underscores ongoing vulnerabilities at centralized exchanges despite improved security practices. Rapid conversion of stolen assets into ether and other native tokens, followed by movement through mixers and bridges, continues to challenge recovery efforts.
While some funds have been frozen, the bulk remains in attacker-controlled wallets as investigations proceed. Industry observers note that such high-value, targeted operations by sophisticated state actors remain one of the most persistent threats to the crypto ecosystem.



