AltcoinBuzzAltcoinBuzz
Subscribe
  • Crypto News
  • Crypto Research
  • Technical Analysis
AltcoinBuzzAltcoinBuzz

An independent digital media outlet delivering crypto research, news, and technical analysis to a community of 600,000+ users.

Follow us on:

Discover

  • Crypto Research
  • Crypto News
  • Technical Analysis
  • Key Opinions
  • Upcoming Launches

Categories

  • Bitcoin BTC
  • RWA
  • Technology
  • Altcoins
  • Regulation

Company

  • Affiliates
  • Partners & Sponsors
  • Careers
  • Contact
  • Terms of Use
  • Subscription Terms
  • About the ALTCOIN BUZZ
  • Privacy Policy
  • Contact ALTCOIN BUZZ
  • Advertise with us

Copyright 2026 ALTCOIN BUZZ. All rights reserved.Something is buzzzzzzzing.
HomeCrypto NewsBitget Hack: $387M Stolen, North Korea Link Identified
Crypto NewsTechnologyAltcoins

Bitget Hack: $387M Stolen, North Korea Link Identified

Chainalysis linked the $387 million Bitget theft to North Korea. No recovered funds or link to the NEAR Intents hack have been confirmed.

AAnmol Billa•Oct 2, 2026
A comic Bitget exchange vault is breached as an attacker redirects $387 million through blockchain paths on the right, with a large headline on the left.
MentionedXRP$1.47-2.00%ETH$2,667.85-1.27%ZEC$1,288.62-3.21%NEAR$4.63-4.45%

Bitget says it lost about $351.6 million in unauthorized transfers, while Chainalysis values the theft at $387 million and attributes it to North Korea-linked actors. The exchange said its $464 million User Protection Fund would cover the loss, but no recovered funds have been confirmed.

That recovery claim matters because it would change who bears the loss. Nothing in the available reporting confirms that any stolen Bitget funds have returned, and no source links returned money to the separate $3.8 million NEAR Intents exploit.

What Happened to the $387 Million

Chainalysis said that DPRK-attributed threat actors stole $387 million from Bitget on September 24, 2026. It said the theft pushed crypto stolen by North Korea-linked actors during the year past $1 billion.

The figures differ. TRM Labs put the loss at about $351.6 million, based on funds moved from Bitget's hot and warm wallets across seven blockchains. The available reports do not explain the gap between the two estimates.

TRM said Bitget detected the transfers at 18:31 UTC and paused withdrawals. The exchange said cold wallets were unaffected.

How the Funds Moved

Chainalysis traced $387 million leaving Bitget in 23 transfers within three hours. The funds landed across four chains:

  • Ethereum: 49.7%
  • XRP: 40.8%
  • Zcash: 7.6%
  • Tron: 1.8%

The attackers did not send the stolen XRP directly to an exchange. Chainalysis said they used a cross-chain liquidity protocol to obtain Bitcoin, which then reached attacker-controlled addresses under monitoring. The available reporting identifies THORChain as the protocol used to swap the XRP.

TRM also found that funds on BNB Chain and Ethereum were swapped through THORChain. It said the assets were then split across Bitcoin addresses in peel chains, a method for spreading funds through sequential transfers.

Chainalysis said its in-house AI tools reduced more than 20 hours of manual bridge reconciliation to under 10 minutes.

Why Bitget's Keys May Not Matter

Bitget did not report a private-key theft. It said the attackers compromised a backend system, manipulated the transaction data shown to the authorization process, and caused it to approve the transfers.

That is a different failure from an exchange losing its signing keys. The authorization system was presented with altered transaction data, so the exchange approved transfers that were not part of the legitimate process.

The distinction may matter to account holders. It means the incident was not limited to a compromised cold wallet, although Bitget has said the affected hot and warm wallets were covered by its User Protection Fund.

North Korea Link Is Strong, but Not Final

Chainalysis attributes the theft to DPRK-linked threat actors. Bitget CEO Gracy Chen has also called North Korean involvement very likely, citing IP addresses linked to VPN services associated with a North Korean hacking group.

TRM is more cautious. It has not definitively attributed the attack, although it found on-chain links to previously identified North Korean thefts, including the Bybit and AFX Bridge incidents. Those links point toward North Korean involvement, but they do not amount to a confirmed attribution from a law enforcement agency.

The return of the funds remains the central unresolved issue. No available source confirms that Bitget has recovered any money from the attackers, and the available reporting does not connect any recovery to the separate NEAR Intents incident.

The NEAR Intents Return Is a Separate Matter

NEAR Intents reported a theft of about $3.8 million. Its general manager, Alex Shevchenko, identified the attacker, posted three addresses for the return of the funds and gave the attacker 48 hours to cooperate.

The exploiter sent 1 BNB to a recovery wallet. As of early October 2, none of the three posted addresses had received the full returned funds, according to the available report.

That incident is far smaller than the Bitget theft and involves a different protocol and victim. The available evidence does not support a link between the two cases.

The information discussed by Altcoin Buzz is not financial advice. This is for educational, entertainment, and informational purposes only. Any information or strategies are thoughts and opinions relevant to the accepted levels of risk tolerance of the writer/reviewers and their risk tolerance may be different than yours. We are not responsible for any losses that you may incur as a result of any investments directly or indirectly related to the information provided. Bitcoin and other cryptocurrencies are high-risk investments so please do your due diligence.

Copyright Altcoin Buzz Pte Ltd.

Related

A comic reserve vault holding USDC and EURC is linked to a bank and an EU consultation document, illustrating Circle's request for looser stablecoin reserve rules.
StablecoinsRegulation
Oct 2, 2026

Circle Wants EU to Loosen Stablecoin Bank Deposit Rules

Circle wants MiCA to replace rigid bank deposit limits with liquidity rules, but its proposal leaves the effect on USDT and redemption terms unclear.

USDC
Anmol Billa
A pop-art illustration shows the Blast network shrinking beside a bridge sending assets back to Ethereum, with a speech bubble announcing BLAST SHUTDOWN and a badge showing $1,793.
Ethereum ETHDeFi
Oct 2, 2026

Blast to Shut Down After TVL and Revenue Collapse

Blast says operating costs now exceed revenue. Users have until Oct. 26 to withdraw through its interface as about $63.5 million remains bridged.

ETH
Shashwat Gupta
A pop-art illustration shows a shrinking Cardano DeFi vault beside USDrf and sUSDrf credit tokens, with a small $67M locked figure and a warning that credit and liquidity risks remain.
DeFiRWA
Oct 2, 2026

Cardano DeFi Falls as RealFi Launches Credit Tokens

Cardano DeFi TVL has fallen by more than half. RealFi's new credit tokens offer yield, but retail exits carry key risks.

ADA
Anmol Billa