TTO-2026-0925-166 · September 25, 2026 Data BreachCryptocurrency

Bitget Crypto Exchange Loses $352 Million in North Korea-Linked Hack via Spoofed Transfers — Circle and Tether Freeze Wallets

bitget.com$351.6 million stolenNorth Korea-linked attributionSpoofed transfer mechanismCircle / Tether freeze wallets$36 million recovered

Summary

Bitget has confirmed a hack in which approximately $351.6 million in digital assets was stolen through a spoofed transfer mechanism that bypassed normal withdrawal controls without requiring private key compromise. Bitget attributed the attack to North Korea-linked actors. Circle and Tether froze USDC and USDT in identified attacker wallets, recovering approximately $36 million. Bitget states its insurance fund will cover user losses. This is one of the largest single exchange hacks on record.

Timeline

DateEvent
Sep 23-24, 2026Bitget hack via spoofed transfer mechanism; $351.6 million drained
Sep 24, 2026Bitget confirms hack; Circle and Tether freeze attacker wallets; approximately $36 million recovered
Sep 25, 2026North Korea-linked attribution confirmed by on-chain analysts; TTO-2026-0925-166 published

What Happened

The Bitget hack exploited a spoofed transfer mechanism rather than private key compromise — attackers manipulated transfer validation logic or internal accounting to authorize withdrawals appearing to originate from legitimate internal processes. The specific technical mechanism has not been fully disclosed. The North Korea attribution is based on on-chain movement patterns, wallet clustering, and bridging behavior consistent with prior Lazarus Group campaigns. Circle’s and Tether’s coordinated freeze recovered approximately 10% of the total theft. The remaining approximately $315 million is in active laundering. Cryptoslate reported the theft could drain approximately 76% of Bitget’s proof-of-reserves if the insurance fund claim does not hold — a solvency concern Bitget has publicly disputed.

Domain Intelligence

bitget.com — 61.92

bitget.com scores in the low-trust range at 61.92. Bitget is the hacked exchange. One threat intelligence source has flagged bitget.com but the observation has not been independently corroborated.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 25, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026