Bitget Backend Breach Drains $387.5 Million as DPRK-Linked Launderers Expose Themselves
Attackers compromised Bitget's backend wallet infrastructure on September 24, stealing $387.5 million; ZachXBT exposed DPRK-linked launderers seeking swap help in public chats.
Bitget detected unauthorized transfers at 18:31 UTC on September 24, 2026, losing approximately $387.5 million from hot and warm wallets across XRP, ETH, USDT, ZEC, USDC, BNB, AVAX, TRX and other assets, including about 102.93 million XRP ($157.5 million) and 31,890 ETH ($85.75 million). Attackers compromised a critical backend component, spoofed transaction data, and induced the platform's authorization process to approve fraudulent transfers without stealing private keys. ZachXBT exposed Chinese illicit actors using five aliases who openly requested support for stalled XRP-to-BTC swaps in public Discord and Telegram channels; one alias also laundered funds from the $292 million Kelp DAO exploit. Bitget attributes the operation with high confidence to a DPRK-linked group; Mandiant and SlowMist are assisting and withdrawals resumed in phases from September 28.
- $387.5 million stolen from hot and warm wallets via spoofed transaction authorization, no private keys compromised
- Laundering route traced through THORChain and a Wasabi CoinJoin round ending in roughly 4.59 BTC
- Chinese laundering aliases exposed themselves requesting swap support in public Discord and Telegram channels
- Attributed with high confidence to a DPRK-linked group; Mandiant and SlowMist assisting
- Withdrawals resumed in phases starting with Bitcoin on September 28
Full article643 words · extracted from cybersecuritynews.com · click to collapse
Cryptocurrency exchange Bitget has begun restoring withdrawals after attackers exploited its backend wallet infrastructure on September 24, stealing approximately $387.5 million from hot and warm wallets.
The incident did not involve stolen private keys, and Bitget said its offline cold wallets and separate self-custodial Bitget Wallet service remained unaffected.
Nevertheless, the breach demonstrates how attackers can bypass strong key protection by compromising the systems that prepare, validate, and authorize blockchain transactions.
Bitget detected unauthorized transfers at 18:31 UTC and activated its emergency response procedures before suspending withdrawals. CEO Gracy Chen said the intruders compromised a critical backend component, spoofed transaction data, and induced the platform’s authorization process to approve fraudulent transfers.
Bitget Backend Breach
The exchange initially estimated losses at $351.6 million, but later raised the figure after tracing additional Zcash and TRON transactions. The affected assets included XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX.
XRP represented the largest known portion of the theft. On-chain analysis identified about 102.93 million XRP, valued near $157.5 million, along with 31,890 ETH worth about $85.75 million. Much of the stolen value was subsequently converted, bridged, or redistributed across networks, complicating recovery and giving investigators a rapidly changing trail to follow.
Blockchain investigator ZachXBT later exposed a striking operational-security failure among people allegedly laundering the proceeds for the suspected North Korean attackers.
According to his findings, Chinese illicit actors using five aliases openly requested technical support in public Discord servers and Telegram channels when swaps involving stolen assets stalled.
— ZachXBT (@zachxbt) September 28, 2026BREAKING: Chinese illicit actors laundering funds from the $387M Bitget exploit on behalf of the alleged DPRK attackers are openly asking for support with orders in public Discord servers and Telegram channels of services they use.
Notably, Alias 4 (below) was also seen… pic.twitter.com/KfdTo51M2o
Screenshots show users asking why large XRP-to-BTC orders had not completed, publishing transaction identifiers and tagging service operators, effectively exposing their own laundering activity while seeking assistance.
The aliases visible in ZachXBT’s transaction map include “jack,” “HELP ME,” “Melon,” “Cc,” and “lolo/Marin.” One account reportedly complained that it had sent 277,724 XRP but received only 431 XRP back after a duplicate transaction was refunded.
The map connects these users through intermediary wallets associated with the Bitget theft and shows flows toward THORChain. ZachXBT said Alias 4, identified as lolo or Marin, had also participated in laundering funds from the $292 million Kelp DAO exploit earlier in 2026.

Investigators have observed the proceeds moving through cross-chain bridges, asset swaps and privacy tools. AMLBot traced one route from TRX to USDT, across USDT0 to Ethereum, into roughly 145 ETH, through THORChain and finally into about 4.59 BTC.
Approximately four BTC then entered a Wasabi CoinJoin round, where transactions from multiple participants are combined to make attribution more difficult.
Bitget has attributed the operation with high confidence to a DPRK-linked group, citing IP behavior and on-chain signatures, although no independent authority has publicly issued definitive attribution. Mandiant and SlowMist are assisting the investigation, and law enforcement has been notified. Bitget says its protection fund covers the financial impact and customer balances remain intact.
Withdrawals are returning in phases, beginning with Bitcoin on September 28, followed by Ethereum on September 29, USDT on September 30, and other tokens, fiat and peer-to-peer services on October 2.
The exchange says it has remediated the exploited vulnerability and that no further unauthorized transfers are possible, while investigators continue tracing and attempting to freeze the stolen assets.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.