Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.
North Korean Hackers Suspected in $387.5 Million Bitget Crypto Heist, Largest Theft of 2026

A $387 million backend breach, not a stolen key
Bitget detected unauthorized transfers from its hot and warm wallets at 18:31 UTC on Thursday, September 24, according to a company statement posted on X. Within about an hour, on-chain investigators had already tracked roughly $183 million leaving wallets tied to the exchange, Decrypt reported.
That number kept climbing. Bitget's confirmed total hit $351.6 million when the company went public with the breach, then rose again to $387.5 million the next day, and Bitget later cited on-chain tracing putting transferred assets at approximately $390.06 million, according to The Hacker News.
CEO Gracy Chen said the attackers never obtained Bitget's private keys. Instead, she said, they compromised a critical backend system inside the exchange's wallet infrastructure, spoofed transaction data, and tricked the company's own authorization process into approving transfers that looked routine. "Private key compromise has been ruled out," Chen said, according to CNBC.
The stolen assets, including ETH, XRP, USDT, USDC, AVAX and BNB, moved across at least five blockchains: Ethereum, XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum, per CNBC, with The Hacker News adding Optimism and Base to the list of networks involved. The single largest piece was about 103 million XRP, worth roughly $157 million, according to Decrypt's reporting cited by Northeast Times.
Why Chen points to Pyongyang
Chen said investigators identified IP addresses matching VPN services previously used by a North Korean hacking group, and that the attack pattern closely resembled prior North Korean operations. "We think this is very likely to be attacked by North Korea," she said in a livestream, according to Euronews.
Chen also said members of Lazarus, the North Korean state-linked hacking group known for crypto theft, had previously approached her posing as a journalist to arrange a Zoom interview, Euronews reported.
Blockchain analytics firm Elliptic said it found connections between XRP from the Bitget exploit and Ethereum from a prior DPRK-attributed exploit, and identified laundering links between Bitget's stolen funds and addresses tied to the 2025 hack of Dubai-based exchange Bybit, which lost $1.5 billion.
Still, Chen stopped short of a formal confirmation, and Bitget itself says the specific method of system intrusion remains under active investigation with help from Google-owned Mandiant and security firm SlowMist. No government has announced an indictment or criminal charge tied to this specific breach, and the attribution rests on IP patterns, on-chain behavior and resemblance to past operations, not a confirmed identification of individuals.
The money is covered, for now
Bitget says customer balances remain accurate and that deposits and trading continued without interruption throughout the incident. Withdrawals were suspended as a precaution, and the company said it would begin restoring them in stages starting September 28.
The exchange says its User Protection Fund, which held more than $464 million at the time of the attack, will absorb the full loss. That fund was $300 million in 2023, built specifically to cover hacks like this one.
Bitget has launched a Recovery Bounty Program offering 5% to platforms that voluntarily freeze attacker-controlled funds and another 5% if funds are ultimately recovered. Several platforms have already frozen wallets connected to the attack, and Bybit CEO Ben Zhou said his team is standing by to help, updating its LazarusBounty tracking platform, according to CNBC.
A pattern, not an isolated incident
According to TRM Labs, this is the largest cryptocurrency theft reported so far in 2026, and the firm says North Korea is behind roughly three-quarters of all crypto thefts this year through April. The same North Korea-linked group behind the Bitget-style tactics, TraderTraitor, is also known for the theft of $1.5 billion from Bybit and $292 million from KelpDAO's LayerZero bridge, according to The Hacker News. United Nations investigators cited by The Record say North Korea stole more than $2 billion from crypto platforms in 2025 alone. Northeast Times also reported that North Korean hackers were tied earlier in 2026 to a separate theft of $290 million from the platform Drift.
The timing lines up with other recent activity. About a week before the Bitget breach, cybersecurity firm SentinelOne attributed North Korea's TraderTraitor group, the same collective linked to the Bybit and LayerZero bridge thefts, to an attack on an India-based IT services company, according to The Hacker News.
The U.S. government has said proceeds from North Korean crypto theft help fund the country's nuclear weapons and ballistic missile programs, per Euronews. Whether Washington or the affected blockchain foundations move beyond wallet freezes to actual recovery of the roughly $390 million is the open question. Chen has said some chain foundations have already confirmed freezing hacker-controlled addresses, but ahead of Bitget's planned withdrawal restoration on September 28, no figure for funds actually clawed back has been made public.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.