Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow Abuse

Bitget Exchange Loses ~$351.6M (On-Chain (TL-2026-2650) is a critical-severity advanced persistent threat campaign, first published 2026-09-25. It is attributed to TraderTraitor (North Korea) with medium confidence, affects Bitget Bitget Exchange - hot and warm wallet infrastructure (backend, maps to 10 MITRE ATT&CK techniques (T1020, T1070, T1078), and is covered by 9 detection rules and 15 indicators of compromise.

Key facts for TL-2026-2650

Threat ID
TL-2026-2650
Severity
CRITICAL
Status
ACTIVE
Category
APT
First published
2026-09-25
Last reviewed
2026-09-25
Attribution
TraderTraitor
Attribution confidence
MEDIUM
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
finance, technology, cryptocurrency
Target regions
Global
Detection rules
9
Indicators of compromise
15

Malware and tooling in Bitget Exchange Loses ~$351.6M (On-Chain

Malware and tooling: AppleJeus, Avalanche, Volgmer

On September 24, 2026 at 18:31 UTC, cryptocurrency exchange Bitget detected unauthorized transfers of approximately $351.6 million from a limited number of its hot and warm wallets; independent on-chain trackers (Lookonchain) later tallied ~$356.86 million across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base. CEO Gracy Chen disclosed that the attacker compromised a critical backend system in Bitget's wallet infrastructure, used it to spoof transaction data, and triggered the exchange's own authorization process to move funds out - private-key compromise and forged user withdrawals were ruled out. Attribution to North Korean state-sponsored actors (TraderTraitor / Lazarus cluster) is preliminary: some related IP addresses matched a VPN service used by a North Korean hacker organization, and IP behavior patterns and on-chain analysis are 'highly consistent' with DPRK-linked groups. Cold wallets and customer balances were unaffected, withdrawals remain suspended pending investigation, and Mandiant and SlowMist are investigating alongside law enforcement, Binance and Bybit.

How Bitget Exchange Loses ~$351.6M (On-Chain works

Bitget, one of the world's top-10 cryptocurrency exchanges by volume with more than 125 million users, disclosed on September 25, 2026 that suspected North Korean threat actors had stolen approximately $351.6 million from a limited number of its hot and warm wallets. The unauthorized transfers were first flagged by Bitget's own security systems at 18:31 UTC on September 24, 2026, with funds still observed moving as late as 21:41 UTC. CEO Gracy Chen described the mechanism during a live Q&A and in X posts: the attacker 'compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out.' She likened the technique to slipping forged withdrawal slips through a bank's teller window - 'the vault keys never left the building; someone got into the office that prepares the slips, created paperwork that looked official, and sent it through the same approval window the bank uses every day.' Private-key compromise was ruled out, no forged user withdrawal requests were involved (the attackers 'directly infiltrated the platform's system and transferred funds'), and Bitget does not believe the incident was caused by internal personnel. Preliminary findings point to a compromise of third-party software in the backend wallet stack - Pluang's reporting quotes the CEO that attackers 'likely breached a commonly used tool' and 'manipulated a service that generated false transfer data, which then triggered a signing machine to move funds.' The specific method of system intrusion remains under active investigation and a full technical report was promised.

Independent on-chain analysts (DCF GOD, who first raised the alarm; Bubblemaps; Arkham Intelligence / Emmett Gallic; PeckShield; Hacken) documented two parallel waves of exfiltration. On the EVM side, roughly $183 million in ETH, USDT, USDC, AVAX, BNB, XAUT and other tokens moved from Bitget-labeled wallets across Ethereum, Arbitrum, Avalanche, Optimism, BSC and Base into a single brand-new address, 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee, over about an hour, within roughly 30 minutes of the first wave receiving ~34.75 million USDT, ~12.85 million USDC and 3,000 XAUt (gold-backed tokens), and about an hour later ~24,373 ETH from multiple tagged addresses; the address, created the day of the hack with its first transaction at ~19:05 UTC, is now tagged 'Bitget Exploiter 1' on Etherscan. On the XRP Ledger, two Bitget-labeled wallets plus a third linked account transferred a combined 102,976,680 XRP (approximately $157.5 million) in three payments beginning 19:01 UTC: 2,248,871 XRP from rGDreBvnHrX1get7na3J4oowN19ny4GzFn (labeled 'Bitget Global'), 91,420,943 XRP in a single transaction (8DF2ECF67268117A34B89BE9B452D3E888A22CBF03E5C196AD72D8B414A84195) at approximately 19:16 UTC, and 9,306,866 XRP via rwTTsHVUDF8Ub2nzV2oAeWxfJzUvobXLEf, all to a brand-new XRPL address beginning rwNhefsz. Native XRP cannot be frozen on the XRPL - freeze tools apply only to issued tokens - making the XRP portion the single least recoverable slice of the haul; the only remaining chokepoints are the exchanges and bridges the attacker must transit to cash out. Lookonchain's asset breakdown of the total (~$356.86 million) is: 102,926,478 XRP ($157.48M), 31,890 ETH ($85.75M), 34,751,168 USDT ($34.75M), 21,056,725 USDC ($21.06M), 19,668,852 USDT0 ($19.67M), 3,000 XAUt ($12.82M), 12,719 BNB ($9.88M), 821,012 AVAX ($8.38M), and 20,593,377 TRX ($7.07M). SlowMist's MistTrack tracking hub subsequently flagged 7 XRPL addresses holding ~102,926,478 XRP, 11 EVM addresses (~67,980 ETH, ~5,896 BNB, ~495 WETH, ~218,022 USDT, ~99,989 USDC), and 1 TRON address (~20,593,376 TRX).

The attacker exhibited classic anti-freeze and laundering tradecraft consistent with professional, state-linked financial theft. On Arbitrum, a fresh wallet spent $19.67 million in USDT0 to purchase 7,111 ETH in roughly six minutes via the UniswapX and 1inch Fusion aggregators, paying up to approximately 5% above market - deliberately prioritizing speed over price to convert freezeable stablecoins into ETH, which is 'decentralized and hard to seize,' before Tether or Circle could act. The consolidator address fanned funds out to six or more new wallets within minutes, a standard first laundering step, and funds were split and bridged cross-chain. On the XRP Ledger, the pile was split into five wallets (four holding 20 million XRP each, one holding approximately 22,976,677 XRP), and each hop was seeded with 0.00001 XRP dust payments from unrelated addresses - the signature spam pattern of address poisoning, where scammers hope someone copies the wrong wallet. On September 25 a 33,500 XRP test run transited the Bridgers swap service, flagged by analyst Yfarmx as a test run ahead of a larger cash-out; by then only ~400,105 XRP had left one of the five split wallets while more than 99% of the stolen XRP remained dormant. Analyst Specter published a thin flow-graph link from the Bridgers-swapped XRP to an Ethereum wallet in the TraderTraitor cluster, tied to July 2026's ~$24 million AFX hack, though the connection runs through a single small wallet (~$4,300) and could reflect shared laundering services rather than shared authorship.

Attribution remains preliminary but consistently points to North Korean state-sponsored actors. Gracy Chen stated that 'preliminary investigations found that some related IP addresses matched a VPN service used by a North Korean hacker organization, and the attack patterns were similar to previous actions by North Korean hackers,' and separately that 'based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations.' The incident occurred roughly one week after SentinelOne publicly attributed the TraderTraitor cluster (UNC4899) to an attack on an India-based IT services company, and the reporting frames the heist alongside TraderTraitor's known operations: the February 2025 Bybit theft of ~$1.5 billion (FBI-confirmed Lazarus), the April 2026 KelpDAO LayerZero-bridge theft of ~$292 million (116,500 rsETH, attributed with high confidence by LayerZero), and the July 2026 AFX theft (~$24M). The KelpDAO precedent is a direct technical parallel: the attackers used social engineering against a LayerZero Labs developer to obtain session keys starting March 6, 2026, spent six weeks infiltrating RPC cloud infrastructure, compromised two internal LayerZero-hosted RPC nodes, denial-of-service'd the external RPC node the DVN used as backup so failover landed on attacker-controlled nodes, and patched those nodes' memory to return truthful data everywhere except the DVN - which then confirmed a forged rsETH burn message ('a burn that had never occurred') and released 116,500 rsETH. Both incidents pivot on forged data feeding a legitimate authorization/signing flow: 'every transaction was individually valid' while 'system-state' was falsified. Security firm Blockaid attributed roughly $609 million of first-half-2026 losses to the TraderTraitor cluster, Chainalysis counted $1.34 billion stolen by North Korean groups in 47 heists during 2024, and Elliptic estimated North Korean hackers have stolen over $6 billion in crypto since 2017, with proceeds reportedly funding the ballistic missile program. For the Bitget incident, however, no subgroup has been formally confirmed and the investigation - with Mandiant, SlowMist, law enforcement, Binance Co-CEO (assisting with tracking, recovery and security intelligence) and Bybit's CEO (ready to help track funds) - is ongoing.

Impact and response: Bitget's cold wallets and the overwhelming majority of platform assets were unaffected; customer account balances remain accurate; deposits and trading continued during the security review. Withdrawals were temporarily suspended out of an abundance of caution and remain suspended pending investigators' confirmation (no restart timeline was committed; 'we will announce a timeline as soon as one is confirmed'). Bitget committed coverage from its User Protection Fund (5,500 BTC, worth more than $464 million), reported the incident to relevant institutions, engaged Mandiant and SlowMist as independent third-party investigators (executive Xie Jiayin also entrusted an independent third-party security team), and contacted the foundations of all affected chains; several foundations confirmed they had frozen hacker-controlled addresses, though this is only effective for issuable tokens such as USDT/USDC (precedent: Arbitrum froze ~$71M / 30,766 ETH of KelpDAO exploit proceeds in April 2026 before the attacker could move it). Attacks targeting exchanges and wallets are TraderTraitor's documented specialty per the April 2022 CISA/FBI/Treasury advisory AA22-108A: job-lure spearphishing to employees of crypto companies, trojanized Electron-based trading apps (DAFOM, TokenAIS, CryptAIS, AlticGO, Esilet, CreAI Deck), deployment of the Manuscrypt RAT, code-signing abuse, and compromised legitimate WordPress infrastructure used as C2. No CVE exists for this incident (no software vulnerability in Bitget's products was disclosed), the specific system-intrusion method and full technical report are pending, and the primary SOC exposure is monitoring the attacker-controlled addresses and laundering venues published here.

MITRE ATT&CK techniques used in TL-2026-2650

Exfiltration

T1020 Automated Exfiltration

Defense Evasion

T1070 Indicator Removal; T1078 Valid Accounts; T1684.001 Impersonation

Command and Control

T1090.002 External Proxy

Initial Access

T1195.002 Compromise Software Supply Chain

Execution

T1204.002 Malicious File

Impact

T1565.001 Stored Data Manipulation; T1565.002 Transmitted Data Manipulation; T1657 Financial Theft

Affected products and versions in Bitget Exchange Loses ~$351.6M (On-Chain

  • Bitget — Bitget Exchange - hot and warm wallet infrastructure (backend wallet/custody systems, transfer authorization and signing pipeline)
    Vulnerable versions: All production backend builds prior to 2026-09-24 incident hardening
  • Bitget — Bitget Wallet (self-custodial)
    Fixed in: Unaffected - runs on completely separate and independent infrastructure from Bitget Exchange

Remediation for Bitget Exchange Loses ~$351.6M (On-Chain

Patches

  • Apply vendor security updates for the compromised third-party backend tool once Mandiant/SlowMist identify it; no CVE has been disclosed to date
  • Pursue asset recovery through on-chain freezing mechanisms for issuable tokens (USDT/USDC/arbitrary issued tokens) and through cooperating exchanges and bridges

Immediate actions

  • Blocklist and monitor all attacker-controlled addresses in the IOC set (EVM consolidator 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee tagged 'Bitget Exploiter 1', the Arbitrum anti-freeze wallet 0xe410a2E5710Ee787bcaa63f52A3943ff71F0d946, the fan-out destinations, the XRP Ledger movement tracked via tx 8DF2ECF67268117A34B89BE9B452D3E888A22CBF03E5C196AD72D8B414A84195, and the MistTrack-marked set of 7 XRPL + 11 EVM + 1 TRON addresses) with movement alerts at exchanges, bridges, DEX aggregators and OTC desks
  • Confirm issuer-freeze requests with USDT/USDC issuers and chain foundations; several foundations have already frozen hacker addresses, but native XRP (~$157.5M of the haul) is not freezable - watch exchange deposits and bridge transits instead
  • Harden the internal transfer-authorization/signing pipeline until the spoofed-data path is closed; withdrawals remain suspended pending investigator confirmation
  • Rotate and revoke credentials and sessions for wallet-backend services; forensically image and audit the identified third-party backend tool and its dependencies for tampering (supply-chain lead: 'a commonly used tool' generates false transfer data feeding the signing machine)
  • Alert partner exchanges and laundering venues (Binance, Bybit and other CEX/DEX/OTC desks, including Bridgers-linked infrastructure) to the listed addresses; watch for XRP cash-out attempts at exchanges and via bridge services

Workarounds

  • Withdrawals remain suspended pending completion of the security review; deposits, trading and reward functions continue
  • Customer balances are covered by the User Protection Fund (5,500 BTC / more than $464 million)

Longer-term hardening

  • Adopt zero-trust, least-privilege governance over all signing and authorization services, with independent multi-party human approval for large or unusual internal transfers
  • Enforce supply-chain integrity for backend tooling: SBOMs, code-signature/hash pinning, and integrity verification of third-party components before deployment
  • Deploy cross-chain invariant and anomaly monitoring - the explicit lesson from the KelpDAO exploit, where every on-chain transaction looked valid while off-chain verifier/authorization data was forged; validate high-value messages against independent verifiers and monitor chain-state invariants (value released vs. value burned/locked)
  • Add deterministic custody monitoring: alert on backend-originated transfer instructions that lack matching user-intent or business records
  • Conduct independent red-team testing of wallet authorization flows and periodic third-party custody audits (Mandiant/SlowMist) post-remediation

Weaknesses (CWE) in Bitget Exchange Loses ~$351.6M (On-Chain

CWE-345, CWE-290

Timeline of Bitget Exchange Loses ~$351.6M (On-Chain

  • Precedent: Bybit lost ~$1.5B (industry articles cite $1.4B-$1.5B) in the largest crypto heist on record; FBI confirmed Lazarus Group involvement. Bitget's incident is framed alongside it as a TraderTraitor landmark operation.
  • Precedent root cause date: KelpDAO/LayerZero intrusion began - attackers used social engineering against a LayerZero Labs developer to obtain session keys, beginning a six-week infiltration of LayerZero's RPC cloud infrastructure (per the verifier-independence analysis and LayerZero statement).
  • Precedent: ~$292M (116,500 rsETH) drained from KelpDAO's LayerZero bridge - not a smart-contract flaw but an off-chain verification-layer compromise (1-of-1 DVN; two internal RPC nodes compromised, external RPC DDoSed, memory-patched nodes fed a forged rsETH burn to the DVN, which released funds for a burn that never occurred); a second 40,000 rsETH (~$95M) 'phantom packet' attempt was blocked after Kelp paused contracts; on April 20 the Arbitrum Security Council froze 30,766 ETH at an exploiter-linked address.
  • Approximately one week before the Bitget incident (date approximate per later reporting), SentinelOne publicly linked the North Korea-aligned TraderTraitor cluster (UNC4899) to attacks on an India-based IT services company.
  • Bitget temporarily suspends withdrawals as a precaution; deposits, trading and reward functions continue. Company commits User Protection Fund (5,500 BTC / >$464M) coverage and contacts foundations on all affected chains; several later confirm freezing of hacker-controlled addresses (effective only for issuable tokens, not native XRP).
  • 21:41 UTC - last observed unauthorized transfer; funds moved roughly 3 hours after initial detection. Total assessed impact ~$351.6M per Bitget; independent on-chain tally ~$356.86M (Lookonchain).
  • Within ~1 hour, roughly $183M in ETH, USDT, USDC, AVAX, BNB, XAUT and other tokens moved from Bitget-labeled EVM wallets (Ethereum, Arbitrum, Avalanche, Optimism, BSC, Base) into freshly created consolidator 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee (a brand-new address whose first transaction was ~19:05 UTC, later tagged 'Bitget Exploiter 1' on Etherscan), which within ~30 minutes had received ~34.75M USDT, ~12.85M USDC and 3,000 XAUt, and ~1 hour later ~24,373 ETH from multiple tagged addresses.
  • ~19:16 UTC - 91,420,943 XRP (~$143M) moved in one transaction (8DF2ECF67268117A34B89BE9B452D3E888A22CBF03E5C196AD72D8B414A84195); a third transfer of 9,306,866 XRP followed via rwTTsHVUDF8Ub2nzV2oAeWxfJzUvobXLEf; combined total ~102,976,680 XRP (~$157.5M).
  • 19:01 UTC - first XRP Ledger transfer: 2,248,871 XRP moved from Bitget Global wallet rGDreBvnHrX1get7na3J4oowN19ny4GzFn to a brand-new attacker account (destination begins rwNhefsz).
  • 18:31 UTC - Bitget's security systems flag unauthorized transfers from a limited number of hot wallets (14:31 ET); emergency response protocols activated; outflows reportedly quieted ~6 minutes after the first suspicious trade for at least 20 minutes.
  • Preliminary attribution: some related IP addresses match a VPN service used by a North Korean hacker organization; attack patterns similar to previous NK actions; IP behavior patterns and on-chain analysis 'highly consistent' with known patterns of NK hacker organizations. Attribution caveated as preliminary; no subgroup formally confirmed; full technical report promised; withdrawals remain suspended.
  • XRP split into five wallets (four holding 20M XRP each, one ~22.98M) with 0.00001 XRP address-poisoning dust seeded per hop; a 33,500 XRP test run transits the Bridgers swap service (analyst Yfarmx); only ~400,105 XRP has left one split wallet while ~99.6% of the stolen XRP remains dormant; analyst Specter links Bridgers-swapped XRP (via a thin single-wallet graph) to the TraderTraitor cluster and July's ~$24M AFX hack.
  • Anti-freeze behavior documented: a fresh wallet spends $19.67M USDT0 to buy 7,111 ETH in ~6 minutes on Arbitrum via UniswapX and 1inch Fusion, paying up to ~5% above market to beat stablecoin issuer freezes; consolidator 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee fans funds out to six or more new wallets within minutes; funds split and bridged cross-chain.
  • Mandiant and SlowMist engaged as independent third-party investigators; law enforcement notified; Binance Co-CEO confirms assistance with tracking/recovery and shared security intelligence (16:59 UTC announcement); Bybit CEO says the team is ready to help track funds; SlowMist MistTrack flags 7 XRPL + 11 EVM + 1 TRON hacker addresses; CEO X post confirms comprehensive investigation and UPF coverage (15:36 UTC).
  • Public disclosure via X and a live Q&A; CEO Gracy Chen describes the mechanism: compromise of a critical backend system in the wallet infrastructure, transaction-data spoofing, and triggering of the exchange's own authorization process ('forged withdrawal slips through a bank's teller window'). Private-key compromise ruled out; no forged user withdrawals; no insider involvement believed; preliminary lead is compromise of third-party backend software feeding the signing machine.

Sources cited for Bitget Exchange Loses ~$351.6M (On-Chain

More in apt

Detection coverage for TL-2026-2650

As of 2026-09-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2650 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats