Technology

Bitget's $351.6 Million Hack Is 2026's Biggest Crypto Theft Yet

Martin HollowayPublished 2w ago4 min readBased on 12 sources
Reading level
Bitget's $351.6 Million Hack Is 2026's Biggest Crypto Theft Yet
Photo by FranciscoMdS / CC BY-SA 4.0

Suspected North Korean hackers stole about $351.6 million from cryptocurrency exchange Bitget, making it the largest known crypto theft of 2026 to date. The theft was reported on Sept. 25, 2026. TechCrunch

The funds left through unauthorized transfers from hot wallets, the internet-connected wallets exchanges use for active trading. Bitget suspended crypto withdrawals after detecting the breach.

The break-in did not involve stolen private keys, the secret codes that control crypto funds. Bitget said attackers compromised the wallet backend, the software that builds transaction data, and used spoofed or faked data to trigger authorization. CoinDesk The keys remained in place. The authorization logic failed.

For exchange operators, that distinction matters. A key theft means secret material is lost, so teams must rotate keys and review key storage, including HSM boundaries, or the limits of hardware security modules, and signing rules. A backend spoof means the signing system acted on false display data, so attention shifts to interface checks, transaction simulation before signing, and verification through a separate channel.

Bitget said it holds $464 million in its user protection fund to cover the theft. That figure would cover the nominal loss in full if applied directly. The company has given different valuations in past disclosures. Bitget reported the Protection Fund averaged $580 million under its UEX Security Standard framework, and said the fund reached $716 million in June 2025. It also reported a 163% Proof of Reserves ratio under that framework, a public measure of assets held against customer deposits.

Bitget CEO Gracy Chen said the breach was highly consistent with known patterns of North Korean hacker groups. Attribution remains suspicion at this stage, not a formal indictment or confirmed finding.

The incident fits a concentrated pattern in 2026. According to TRM Labs, North Korea was behind around three-quarters of all crypto theft value in 2026 to date. A September 2026 heist involving $340 million saw the hacker return all but $47 million of the stolen funds. Earlier in September, the Bitcoin-based Liquid Network reported that $320 million was withdrawn in a hack. Bloomberg

Bitget has previously described heavy hostile traffic. Between July 2025 and June 2026, its security systems intercepted more than 150 million malicious requests. Earlier in 2026, Bitget listed Immunefi (IMU) on Launchpool and Spot trading. Listings, APIs, and backend integrations widen the attack surface alongside core custody.

The broader context here is where exchange risk now concentrates. Hot wallets stay online for liquidity, so isolation and limits can contain loss but cannot remove it. When the backend that prepares and displays transactions is compromised, even correct key handling will sign incorrect transfers. In my view, that makes clear transaction displays, separate checks on signing intent, and hardware-enforced policy rules more useful than additional perimeter controls.

In my view for practitioners, the lesson is to treat wallet backends as untrusted input. Independent transaction decoding, allowlist enforcement, velocity limits on hot balances, and multisig approval across separate codebases and infrastructure narrow the damage from a single false view. Full reimbursement restores balances, but it does not restore confidence in the signing pipeline. Past incidents have usually produced better defaults, from Proof of Reserves publication to clearer fund disclosures, and this event is likely to speed work on verifiable transaction intent.