Anatomy of the Bitget Heist: When the Approval System Is the Attack Surface
What happened
Bitget says its security system detected unauthorized transfers involving certain hot and warm wallets at 18:31 UTC on September 24. The company paused withdrawals, and Mandiant and SlowMist are assisting with the investigation. In its October 4 update, Bitget gives a final verified figure of approximately $388M, involving 12 wallet addresses, all of them hot or warm wallets. Cold wallets were unaffected. Bitget lists the affected assets as XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX, across Ethereum and multiple EVM networks, the XRP Ledger, Zcash and TRON.
In September, press reports quoted Bitget as saying that preliminary evidence, including IP patterns tied to VPN services previously used by a North Korean group and on-chain behavior, pointed to North Korean attackers. Bitget's October 4 incident page does not address attribution. Elliptic reported links between some of the stolen funds and addresses tied to earlier hacks, including Bybit's in 2025. It estimated that the attack pushed North Korea's crypto thefts past $1 billion for 2026.
Confirmed vs. still under investigation
| Item | Status |
|---|---|
| Unauthorized transfers from hot and warm wallets; cold wallets unaffected | Reported by Bitget |
| Loss size: approximately $388M, 12 wallet addresses (Bitget, final verified figure, October 4). Earlier estimates: ~$351.6M initial; ~$387.5M revised. | Final figure (Bitget) |
| Private keys not compromised; cold wallets unaffected | Bitget incident page |
| Intrusion method: a zero-day in a third-party security product used to steal internal credentials, then forged withdrawal commands written directly into the wallet system, bypassing risk control verification. Traces were later deleted. | Bitget incident page |
| Formal security report with full technical details | Not yet published |
| North Korean attribution | Suspected, not formally confirmed |
Why this one matters
Most treasury security thinking focuses on keys: who holds them, how they are split, where they are stored. Bitget's account points to a different failure mode. If the attacker can write withdrawal commands below the risk checks, key security never gets tested. The wallet processes each transfer as a normal withdrawal.
If the press reports are correct, this fits a broader pattern. North Korean groups have increasingly targeted the people and processes around the keys: fake recruiters, fake investor pitches to executives, insiders placed through IT hiring, and signer compromise staged over weeks. The target is the approval path, not the vault.
The control lesson: a gate that doesn't trust upstream
An independent pre-broadcast layer evaluates every outbound transfer on its own terms, regardless of what upstream systems approved. For the pattern reported here, transfers from hot and warm wallets to destinations outside normal flows, several independent checks are designed to fire:
We don't know Bitget's internal architecture, and we are not claiming any specific product would have prevented this incident. The point is structural: controls that share a failure path with the approval system can be bypassed together.
Five questions every treasury should answer this week
- If our internal approval system were compromised, what would stop an outbound transfer?
- Are velocity limits enforced outside the system that initiates transfers?
- Can funds go to a never-seen address without separate verification?
- Is our second approval collected through an independent channel?
- Could we reconstruct every approval decision within an hour of an incident?
See the pattern in action
We built a simulation modeled on early public reporting: a burst of hot-wallet transfers to new addresses, run with and without an independent pre-broadcast gate. It runs on test infrastructure, not Bitget systems.
Simulation based on public reporting. Not Bitget systems. Investigation ongoing.
Check your treasury's exposureSources
- Bitget: official security incident page (last updated October 4, 2026; supersedes the figures below)
- CNBC: Bitget suspects North Korea in $352 million hack
- Fortune: North Korea accused of plundering Bitget for $387 million
- Bloomberg: Crypto theft by North Korea tops $1 billion in 2026
- SecurityWeek: North Korea suspected in $351 million Bitget heist
- BleepingComputer: Hackers steal $351.6 million in Bitget hack
- Elliptic: Bitget attack pushes suspected North Korea crypto heists over $1 billion in 2026
- Decrypt: Bitget hack losses climb to $387M
This analysis relies only on public reporting and is no longer updated. For current facts, use Bitget's official incident page. CryptOps is not affiliated with Bitget. Nothing here is investment advice.