North Korean-linked hackers executed a cyberattack against cryptocurrency exchange Bitget on Thursday, making off with more than $351 million in digital assets. The theft represents the largest known cryptocurrency heist of 2026, surpassing a previous $340 million hack from September where the attacker ultimately returned all but $47 million of the stolen funds. The breach targeted Bitget's hot wallets—internet-connected systems designed for active trading operations—resulting in unauthorized transfers of cryptocurrency.
Bitget responded quickly to the breach by suspending cryptocurrency withdrawals across its network. The exchange's chief executive, Gracy Chen, acknowledged that the attack's characteristics aligned closely with documented patterns of North Korean hacker organizations. Bitget stated it maintains a $464 million user protection fund, which the company indicated should be sufficient to cover the losses from the theft. However, Chen did not specify when withdrawal services would be restored to normal operations.
This incident reflects an escalating pattern of high-profile attacks targeting the cryptocurrency sector. North Korean hacking collectives have been previously linked to numerous cryptocurrency thefts and have demonstrated capability in targeting open-source software repositories to conduct mass compromises. Security analysts believe these operations help fund the nation's nuclear weapons development program. According to blockchain intelligence firm TRM Labs, North Korea has been responsible for approximately three-quarters of all cryptocurrency thefts throughout 2026, establishing the country as a dominant actor in financially motivated cybercrime against digital asset platforms.
The Bitget breach underscores persistent vulnerabilities within cryptocurrency exchange infrastructure despite repeated high-profile attacks. The targeting of hot wallets—which by necessity maintain internet connectivity for operational efficiency—highlights the inherent security tension between accessibility and protection. The frequency and scale of North Korean-attributed attacks suggest that traditional cybersecurity measures have proven insufficient against state-sponsored adversaries with significant resources and technical sophistication. The incident may prompt renewed industry discussion about custody arrangements, cold storage protocols, and the feasibility of maintaining large liquid reserves on internet-connected systems.
Gist is a free AI reader for your browser, iPhone, and Android. Get concise summaries and key takeaways from any article or podcast.
Get Gist — Free