Bitget reports $351M breach; CEO cites DPRK-linked VPN IPs and says wallet keys were not obtained
Bitget detected unauthorized transfers from several wallets on Sept. 24. Reports put the losses at roughly $351 million to $352 million; CoinGape reported that XRP accounted for nearly $157.5 million of the stolen assets [1] [2] [3] [4].
CEO Gracy Chen said a preliminary investigation found IP addresses using VPNs associated with a DPRK-linked group, making North Korean involvement “very likely.” Chen also said the attackers breached Bitget’s internal system and did not obtain private keys to its hot, warm or cold wallets [1] [2].
Anonymous feedback used to improve internal story ranking. No public totals are shown.
Share
Share this article
Share this article on social platforms.
Support ClusterWire
If you find ClusterWire useful, tips help cover hosting and infrastructure costs.
We record anonymous interactions with tip buttons to understand feature usage. We do not include IP addresses, user-agent strings, or wallet addresses in these tip analytics. Blockchain transactions are public and may reveal the sending address.
Sources
Review the sources used to produce this brief. Citations open the referenced material in a new tab.
- 1Highlight Clip: Bitget CEO: $350M Hack Very Likely Linked to North KoreaWu Blockchain• Sep 25, 2026
- 2Bitget CEO suspects North Korea behind $352M hack, citing IP cluesCointelegraph• Sep 25, 2026
- 3North Korea Behind the $351.6M Bitget Hack? What You Need to KnowCoinpaper• Sep 25, 2026
- 4Over $157M in XRP Stolen in Bitget Hack, North Korea’s Lazarus Group SuspectedCoinGape• Sep 25, 2026
Updates and corrections
No changes recorded in the new revision log. Earlier edits may not be included.
Topics
Related Topics
Topics identified from the sources associated with this article.