Home / Blog / 25 September 2026
News · Sep 29, 2026 · 4 min read
Bitget's CEO suspected North Korea within hours of its $351.6 million hack on 24 September. By the next day, the blockchain-forensics firm Elliptic had the evidence: stolen funds moving through the same addresses that laundered 2025's $1.5 billion Bybit heist, the one the FBI already pinned on Pyongyang.
Bitget's security systems flagged unauthorised transfers out of its hot and warm wallets at 18:31 UTC on 24 September, the start of a hack that eventually reached $351.6 million. A suspect emerged in the same hours. Chief executive Gracy Chen described the attack itself — "the attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process" — and then went further than most exchanges do mid-incident, naming a likely culprit: "We've identified some IP addresses that match the VPN choices by a certain DPRK group. The pattern looks very much like what the North Korean team did before," she said, per Gizmodo.
An IP address and a hunch are not proof. By 25 September, the blockchain-analytics firm Elliptic had published the harder kind of evidence, in a report headlined "Bitget attack pushes suspected North Korea crypto heists over $1 billion in 2026".
Elliptic's case was on-chain, not circumstantial. The firm traced the XRP and ether taken from Bitget to addresses already linked to earlier thefts attributed to North Korea's state-backed hacking teams, and found Bitget's proceeds touching wallets used to launder the $1.5 billion Bybit hack of February 2025.
The laundering method matched the pattern too. Stolen stablecoins were converted rapidly into each chain's own native asset — a technique Elliptic has documented across prior DPRK cases — and funds moved on Arbitrum were cross-chained to Ethereum quickly, which Elliptic described as reflecting "lessons learned from the laundering of KelpDAO," an earlier North Korea-linked exploit.
Elliptic was not the only trail. Taylor Monahan, the security researcher who leads fraud detection at MetaMask, separately traced Bitget's stolen funds into an address that had already received money from the Bybit hack, and named the actor directly: Lazarus, the label US and South Korean authorities use for North Korea's state-backed hacking cluster. Two investigators, working independently with different tools, arrived at the same wallets.
The wallets in question are not new to investigators. In February 2025, hackers stole roughly $1.5 billion in ether from Bybit — "the largest cryptocurrency heist in history," as the Center for Strategic and International Studies put it — and the FBI formally attributed it to North Korea in a public alert, naming the operation "TraderTraitor" and describing attackers who compromised a developer's machine tied to Bybit's Gnosis Safe multisig wallet before laundering the proceeds across thousands of addresses on multiple chains, converting some of it to bitcoin along the way.
Bitget's stolen funds running into that same laundering infrastructure nineteen months later is not a fresh accusation dressed up as evidence. It is the same operators' machinery, caught reusing itself.
Add Bitget's loss to everything else attributed to North Korean actors this year and Elliptic puts the 2026 total above $1 billion, the largest annual haul the firm has tracked outside 2025's Bybit-inflated outlier. September alone is already 2026's most expensive month for crypto exploits industry-wide — a total that stood near $684 million once Bitget's confirmed figure was added, as CryptoSlate reported — and Bitget's hack alone accounts for more than half of it.
None of this touches a miner's own coins, because none of them were ever going to be there. The model this site runs on assumes a coin is mined, kept in cold storage, and never handed to an exchange to sit in a hot wallet awaiting a trade — the same argument made from the other direction in our guide on why nobody sells the coins to pay the power bill. A coin that never leaves cold storage cannot appear in an on-chain forensics report a year later, whichever state turns out to be behind the next one.
Network-side, hashprice held close to $40 per petahash per day through the week investigators traced Bitget's wallets back to Pyongyang, exactly where it sat before the story broke. State-sponsored theft from an exchange is a real, recurring and now well-evidenced risk. It is a custody risk, not a mining one, and the two keep getting filed under the same worry for no good reason.
Firsthand Bitcoin sells and hosts mining hardware, including this machine. No manufacturer, distributor or affiliate programme paid for or reviewed this page and we take no commission on the links above. Historical figures are computed from daily bitcoin price and network hashprice, each day valued at its own prices. Nothing here is investment advice.