Investigators trace Bitget breach to third-party zero-day and North Korean hackers
Security researchers and blockchain analytics firms have tied the massive Bitget exchange hack to a third-party security zero-day exploited weeks prior, with Chainalysis attributing the incident to North Korean threat actors.

Blockchain analytics firm Chainalysis and security researchers have linked the multimillion-dollar hack of cryptocurrency exchange Bitget to North Korean cyber actors who leveraged a vulnerability in an external security tool. According to cybersecurity firm SlowMist, Bitget's hot wallets were compromised weeks ahead of the late September breach, with attackers first exploiting a zero-day flaw in a third-party security product as early as Aug. 31. SlowMist noted that the intrusion involved two security products and a custom withdrawal tool.[1][2][8][9]
Bitget CEO Gracy Chen explained in a walkthrough with Laura Shin that the perpetrators used the third-party zero-day to fake withdrawal commands. The outflow began with a 0.48 ETH test transaction before 17 large transfers drained roughly $361 million in an initial round. On Shin's Uneasy Money podcast, Pablo Sabbatella similarly noted that a security product designed to protect the exchange became the entry vector for the attack, while fellow guest Taylor Monahan highlighted North Korean ties and the hackers' rapid exit from Arbitrum. The podcast reported that Bitget covered user losses from the hack, which totaled up to $388 million.[4][5]
Chainalysis attributed the $387 million exploit to DPRK-linked threat actors, deploying in-house artificial intelligence tools to track the loot across four blockchains in an ongoing race against the thieves. Within the first three hours, stolen funds were split across 23 transfers on Ethereum, XRP, Zcash, and Tron, with Ethereum and XRP accounting for 49.7% and 40.8% of the initial movement. Investigators subsequently traced tens of millions in XRP through cross-chain liquidity protocols into Bitcoin over approximately 36 hours. According to Chainalysis, the breach pushed North Korea's total crypto haul for 2026 above $1 billion.[1][3][6][7]
Key facts
- Chainalysis attributed the $387 million Bitget hack to DPRK-linked threat actors and reported that the incident pushed North Korea's 2026 crypto thefts past $1 billion.
- SlowMist reported that Bitget's hot wallets were compromised as early as Aug. 31 through a zero-day vulnerability in a third-party security product.
- The exploit operation involved two security products and a custom withdrawal tool, according to SlowMist.
- Bitget CEO Gracy Chen stated that attackers used the zero-day to fake withdrawal commands, executing a 0.48 ETH test transfer followed by 17 large transfers that took about $361 million in the first round.
- Bitget covered the losses resulting from the hack, according to the Uneasy Money podcast.
- Stolen assets were transferred 23 times across Ethereum, XRP, Zcash, and Tron in the first three hours, with Ethereum representing 49.7% and XRP representing 40.8% of initial movements.
- Chainalysis used in-house AI tools to trace tens of millions of dollars in stolen XRP through cross-chain liquidity protocols into Bitcoin over about a day and a half.
Sources · 8 sources
- WB
Wu Blockchain@WuBlockchainPost on X ·
Chainalysis Attributes Bitget’s $387M Hack to DPRK Actors, Traces Funds Across Four Chains Chainalysis said the $387 million Bitget hack was carried out by DPRK-linked threat actors. Within the first three hours, the stolen funds moved across Ethereum, XRP, Zcash and Tron through 23 transfers, with Ethereum and XRP accounting for 49.7% and 40.8% respectively. Investigators also traced tens of millions of dollars in stolen XRP through cross-chain liquidity protocols into Bitcoin over roughly a day and a half. The attack has pushed total DPRK-linked crypto thefts in 2026 above $1 billion.
Open source - CN
crypto.news@cryptodotnewsPost on X ·
JUST IN: Bitget’s hot wallets were reportedly compromised weeks before the September 25 hack SlowMist has said that attackers exploited a zero-day in a third-party security product as early as August 31, giving them access long before the $350M incident. https://t.co/eMszOtocjQ
Open source - CB
Crypto BriefingArticle ·
Chainalysis links most of the stolen XRP in $387M Bitget hack to North Korea The Bitget hack highlights escalating cyber threats from North Korea, stressing the need for enhanced security measures and rapid response capabilities. The post Chainalysis links most of the stolen XRP in $387M Bitget hack to North Korea appeared first on Crypto Briefing .
Open source - LS
Laura Shin@laurashinPost on X ·
How a Security Product Became the Way Into Bitget's $388M Hack: Uneasy Money A security product meant to protect @bitget became the way in for a $388M hack, @pablosabbatella explains. 🔐 On Uneasy Money, he joins @kain, @tayvano_, and @austingriffith to trace what happened and why the funds raced off @arbitrum. Timestamps: 🚨 02:32 How Bitget got hit for $388M and covered the losses 🛡️ 08:24 Why Pablo says a third-party security product was the way into Bitget 🕵️ 11:22 Taylor ties the hack to North Korea and highlights their rush to exit Arbitrum ❄️ 13:34 Pablo on why security councils restart the freeze debate every time ⛓️ 14:17 Why Kain says THORChain can't claim it's like Bitcoin and Ethereum 🧭 30:24 How NEAR's Shield blocks funds using behavioral anomaly detection 📣 34:51 1inch: See how 1inch Aqua lets LPs back multiple positions with one token balance at https://t.co/2ZfndbOlh7 🤖 36:16 Rogue AI agents are hacking outside systems as the labs eye IPOs 🔓 39:11 Why Pablo thinks the AI labs want to regulate open-source models 📈 48:55 Kain's case for letting retail take the risk on a $2T Anthropic IPO 🧱 01:05:47 Why Kain calls Vitalik's 2030 roadmap the most bullish Ethereum read in years 🏪 01:19:18 Pablo asks whether Ethereum's real challenge is commercial, not technical
Open source - LS
Laura Shin@laurashinPost on X ·
A 0.48 ETH test. Then 17 large transfers. About $361M gone in the first round. 🚨 @GracyBitget walked me through how attackers used a third-party zero-day to fake withdrawal commands at @bitget. https://t.co/dJ3PkML6lC
Open source - DE
DecryptArticle ·
Chainalysis Used AI to Trace the $387M Bitget Hack Back to North Korea The firm says the Sept. 24 breach pushed North Korea's 2026 crypto haul past $1 billion, and detailed how it used in-house AI to trace the stolen funds across four blockchains in a race against the attackers.
Open source - DE
Decrypt@DecryptMediaPost on X ·
Chainalysis Used AI to Trace the $387M Bitget Hack Back to North Korea https://t.co/72VJHXnGuI
Open source - CO
CoinMarketCap@CoinMarketCapPost on X ·
UPDATE: 🚨 SlowMist says Bitget's hot wallets were compromised weeks before the Sept. 25 hack, with a zero-day vulnerability on a 3rd-party security product first exploited as early as Aug. 31. https://t.co/pdfbNQbMjm
Open source - CT
Coin TelegraphArticle ·
SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit SlowMist identified malicious activity weeks before the Bitget theft, involving a zero-day vulnerability, two security products and a custom withdrawal tool.
Open source

