The largest crypto theft of the year: what happened to Bitget and who may have been behind the attack

The largest crypto theft of the year: what happened to Bitget and who may have been behind the attack

Around $351.6M was drained from Bitget's hot wallets, and according to the exchange the attackers never gained access to its private keys.

Sep 28, 2026

On September 24, 2026, attackers drained around $351.6M from the hot wallets of the crypto exchange Bitget across several blockchains at once: Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain and Base. Bitget detected the unauthorised transfers at 18:31 UTC, suspended withdrawals and stated that the loss is covered by its Protection Fund. As things stand, this is the largest crypto theft of 2026 by value.

How the attack was carried out

Crypto exchanges use hot wallets to process withdrawals, while the bulk of customer assets is held in cold wallets. Transfers from such wallets still require confirmation before the transaction is signed. Bitget's chief executive Gracy Chen said that the attacker gained access to an internal system connected to the wallet infrastructure, substituted the transaction data and triggered the authorisation process. Bitget maintains that its private keys were not compromised and that its cold wallets were unaffected.

In some respects this failure resembles the Bybit theft of February 2025: in both cases the attacker manipulated the information seen by the people or systems responsible for confirming the transfer. With Bybit, this led signers to approve a transfer from a cold wallet. With Bitget, according to the exchange's statement, the substituted data made the protection system confirm transfers from hot wallets.

Within hours the stolen funds were spread across wallets in round amounts

On Ethereum, a significant share of the stolen funds passed through the address 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee, which also received funds through Arbitrum, Avalanche, Base, BNB Chain and Optimism. Another wallet, 0xa6dd3f218b65e32ccc37be30f74884133c655545, spread its funds across newly created wallets over roughly two hours on the evening of September 24. Most of them received around 10,000 ETH. Together with the wallets funded directly from the first address, eight wallets received the bulk of the stolen ETH. By the morning of September 25, none of them had sent the funds any further.

Much the same happened with XRP. Funds withdrawn from Bitget passed through small intermediate wallets and then arrived at separate accounts, where they were held in large round amounts of 20M XRP. Most of these XRP were also still in place as of the morning of September 25.

Part of the stolen funds has already started moving towards bitcoin. Funds on BNB Chain and Ethereum were swapped through THORChain and distributed across bitcoin addresses along so-called peel chains - sequences of transfers in which part of the funds is separated from the main amount. On TRON, the stolen TRX was swapped for USDT through SunSwap, then moved to Ethereum via USDT0 and entered the same route through THORChain. Smaller amounts went through Across, Bridgers, Chainflip and FixedFloat.

The attackers' addresses were flagged and classified as linked to the September 2026 attack on Bitget. These labels have expanded from Ethereum to other networks, including the XRP Ledger and Bitcoin, and cover intermediate wallets further along the chain of movement.

Below is one of the routes the funds took after the attack: from Bitget's hot wallet on BNB Chain through THORChain. Around $9.8M in BNB left Bitget on the evening of September 24 and passed through several attacker wallets and intermediate addresses before being split into smaller amounts. Over the next roughly 13 hours, individual portions of the funds reached THORChain in transfers of a few hundred thousand dollars each and were converted into bitcoin.

One of the routes the funds took after the attack on Bitget on BNB Chain - from Bitget's hot wallet through attacker wallets and intermediate addresses to THORChain. Visualization: TRM Labs
One of the routes the funds took after the attack on Bitget on BNB Chain - from Bitget's hot wallet through attacker wallets and intermediate addresses to THORChain. Visualization: TRM Labs

What is the assumption of North Korean involvement based on?

Bitget's chief executive Gracy Chen said that North Korean involvement is «highly likely», citing IP addresses that the exchange's preliminary investigation linked to VPN services associated with a North Korean hacking group. As during the Bybit theft of February 2025, which the FBI linked to North Korea, the attacker manipulated the information used to confirm the transfer rather than stealing private keys.

Tracing the stolen funds on-chain revealed several overlaps with wallets used to launder money after previous North Korean attacks, including the attacks on Bybit and AFX Bridge. At the very least, these on-chain links show that the laundering relies on the same infrastructure the TraderTraitor group used in other recent attacks. This laundering network has not previously been associated with thefts by other hacking groups, so the overlaps found point to TraderTraitor. More conclusive technical evidence of the connection may emerge in the coming days.

The way the funds were laundered after the Bitget attack matches the pattern of recent North Korean thefts. Within a few hours the money was spread across new wallets in large round amounts, after which most of it simply stayed put. The portion that has already started moving went through swap services, including THORChain, and was converted into ETH and BTC. That said, such services and methods are available not only to North Korean groups.

What should compliance teams prepare for?

The funds that have not moved yet remain the main question. As of the morning of September 25, most of the stolen ETH and XRP was still sitting in the wallets described above. After the Bybit theft, a significant share of the converted bitcoin also stayed almost motionless for a long time before the next laundering stage began, through mixers and over-the-counter (OTC) networks. After the attack on Drift, part of the funds likewise sat untouched in new wallets.

Crypto mixers: how they work and what their trace in a wallet history meansSep 3, 2026Read more

When the Bitget funds do start moving, the route already used may suggest where they are most likely to surface. Funds that pass through cross-chain bridges, cross-network swap services and Bitcoin peel chains usually reach exchanges after several intermediate hops, rather than directly from an address linked to the attack. That is why such a deposit can only be tied to the original theft by tracing the movement of funds across several wallets and different blockchains.

#Cryptoexchange#Cryptofraud
The trail leads to North Korea: how the largest crypto theft of 2026 was carried out