Bitget Backend Breach Drains $387.5 Million as DPRK-Linked Launderers Expose Themselves
Attackers compromised Bitget's backend wallet infrastructure on September 24, stealing $387.5 million; ZachXBT exposed DPRK-linked launderers seeking swap help in public chats.
Bitget detected unauthorized transfers at 18:31 UTC on September 24, 2026, losing approximately $387.5 million from hot and warm wallets across XRP, ETH, USDT, ZEC, USDC, BNB, AVAX, TRX and other assets, including about 102.93 million XRP ($157.5 million) and 31,890 ETH ($85.75 million). Attackers compromised a critical backend component, spoofed transaction data, and induced the platform's authorization process to approve fraudulent transfers without stealing private keys. ZachXBT exposed Chinese illicit actors using five aliases who openly requested support for stalled XRP-to-BTC swaps in public Discord and Telegram channels; one alias also laundered funds from the $292 million Kelp DAO exploit. Bitget attributes the operation with high confidence to a DPRK-linked group; Mandiant and SlowMist are assisting and withdrawals resumed in phases from September 28.