Sunday, October 4, 2026Live markets
BBTC$85,951.19 +1.45%EETH$2,706.85 +0.76%BBNB$794.08 +1.03%XXRP$1.51 +1.56%SSOL$121.46 +1.48%TTRX$0.3357 +0.12%HHYPE$90.76 +1.42%ZZEC$1,338.72 +1.67%DDOGE$0.0974 +4.75%LLINK$14.21 +1.23%XXMR$548.95 -1.93%AADA$0.2540 +3.69%XXLM$0.2206 +2.30%NNEAR$4.93 +3.68%
Security

Chainalysis Ties $387M Bitget Hack to North Korea

CDBy · · 3 min read
Chainalysis Ties $387M Bitget Hack to North Korea

Chainalysis has attributed the $387.5 million Bitget exchange hack to hackers tied to North Korea, a finding that lifts the total value of crypto stolen by DPRK-linked groups in 2026 past $1 billion, according to Blockonomi. The breach hit on September 24, and investigators traced the stolen XRP through a cross-chain liquidity protocol into Bitcoin addresses held by the attackers.

Bitget first put the loss at $351.6 million before revising it upward, Cryptobriefing reported. The exchange said the change reflected fuller accounting of Zcash and Tron transfers rather than a second wave of unauthorized withdrawals, and that it had identified and fixed the underlying vulnerability.

Key facts

  • Chainalysis published its findings on October 1, attributing the $387 million theft to DPRK-linked actors and saying North Korea-attributed crypto theft topped $1 billion in 2026.
  • Funds left Bitget in 23 transfers within the first three hours: Ethereum took 49.7%, XRP Ledger 40.8%, Zcash 7.6% and Tron 1.8%, per Chainalysis.
  • Bitget detected unauthorized transfers at 18:31 UTC; attackers did not take private keys, instead compromising a backend wallet system and spoofing transaction data to pass the exchange’s own authorization checks, Cryptobriefing reported.
  • Roughly 103 million XRP, worth about $157 million, was the single largest asset category taken, Cryptobriefing reported.
  • PeckShield recorded $766.49 million across 55 major hacks in September, approximately 462% above August, with Bitget the largest incident.

A money trail across four chains

Decrypt and Chainalysis both described the same pattern: rather than sending the XRP to an exchange account, the attackers ran it through a cross-chain liquidity protocol and pulled Bitcoin out on another network, moving tens of millions of dollars that way over roughly 36 hours before the trail reached attacker-controlled Bitcoin addresses now under monitoring.

Independent analysis from Bitquery reported by Blockonomi identified THORChain as a route used to convert the stolen XRP, finding on September 29 that 90.5% of it had become Bitcoin. Decrypt reported that Near Intents rejected more than $50 million in swaps tied to the hacker, only to be hacked itself days later, while THORChain kept processing. The same report said Circle and Tether froze roughly $318,000 in stablecoins. Cryptobriefing put the overall freeze rate at only about 0.2% of the stolen funds.

Chainalysis said its team built in-house AI tracing tools that compressed what it estimated as more than 20 hours of manual bridge reconciliation into under 10 minutes, a claim it stressed accelerated investigators rather than replacing them. The investigation also includes Mandiant and SlowMist, and Bitget has published attacker addresses so other platforms can monitor affected assets.

Why it matters

Bitget is the first victim to confirm a revised loss for this hack, and the October 1 attribution now sits alongside other third-party assessments. Bitget CEO Gracy Chen flagged a North Korean connection shortly after the theft, citing suspicious IP addresses linked to VPN services a DPRK group had used before; Blockonomi reported the attribution follows those earlier suspicions, and Decrypt noted Elliptic called a DPRK link “highly likely.”

The absence of stolen private keys is the detail with the widest implications for exchanges: because the attackers corrupted the systems that decide whether a withdrawal is legitimate, they made the platform approve its own loss. Chainalysis’s finding also sits against its estimate that North Korean hackers took more than $2 billion during 2025, and against TRM’s assessment that April’s Drift Protocol and KelpDAO attacks, $285 million and $292 million respectively, made up 76% of crypto hack losses through that month.

For customers, the recovery question is separate from the tracing question. Bitget’s User Protection Fund stands at roughly $464 million, above the loss, and the exchange said it will cover the shortfall and that customer balances are unaffected — money it is unlikely to recover, since almost none of the stolen assets have been frozen.

What to watch

Chainalysis said it is monitoring linked Bitcoin addresses and sharing intelligence with exchanges, issuers and law enforcement. The next concrete data point will be the updated freeze figures — currently around 0.2% of stolen funds — and whether any of the token issuers or protocols holding the funds respond to the addresses Bitget published.

This is not financial advice. Crypto markets are volatile and uncertain, and this article reports third-party findings, not investment guidance.

Disclaimer: This article is for information only and is not investment, financial or trading advice. Cryptocurrency prices are highly volatile. Always do your own research.

Sources: Blockonomi, Cryptobriefing, Decrypt

CD

The CryptoNewsroom editorial desk covers Bitcoin, Ethereum, altcoins, DeFi, regulation and crypto markets. Editorial policy

Related stories