Bitget Backend Breach Drains $387.5 Million as DPRK-Linked Launderers Expose Themselves

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Cryptocurrency exchange Bitget has begun restoring withdrawals after attackers exploited its backend wallet infrastructure on September 24, stealing approximately $387.5 million from hot and warm wallets.

The incident did not involve stolen private keys, and Bitget said its offline cold wallets and separate self-custodial Bitget Wallet service remained unaffected.

Nevertheless, the breach demonstrates how attackers can bypass strong key protection by compromising the systems that prepare, validate, and authorize blockchain transactions.

Bitget detected unauthorized transfers at 18:31 UTC and activated its emergency response procedures before suspending withdrawals. CEO Gracy Chen said the intruders compromised a critical backend component, spoofed transaction data, and induced the platform’s authorization process to approve fraudulent transfers.

Bitget Backend Breach

The exchange initially estimated losses at $351.6 million, but later raised the figure after tracing additional Zcash and TRON transactions. The affected assets included XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX.

XRP represented the largest known portion of the theft. On-chain analysis identified about 102.93 million XRP, valued near $157.5 million, along with 31,890 ETH worth about $85.75 million. Much of the stolen value was subsequently converted, bridged, or redistributed across networks, complicating recovery and giving investigators a rapidly changing trail to follow.

Blockchain investigator ZachXBT later exposed a striking operational-security failure among people allegedly laundering the proceeds for the suspected North Korean attackers.

According to his findings, Chinese illicit actors using five aliases openly requested technical support in public Discord servers and Telegram channels when swaps involving stolen assets stalled.

Screenshots show users asking why large XRP-to-BTC orders had not completed, publishing transaction identifiers and tagging service operators, effectively exposing their own laundering activity while seeking assistance.

The aliases visible in ZachXBT’s transaction map include “jack,” “HELP ME,” “Melon,” “Cc,” and “lolo/Marin.” One account reportedly complained that it had sent 277,724 XRP but received only 431 XRP back after a duplicate transaction was refunded.

The map connects these users through intermediary wallets associated with the Bitget theft and shows flows toward THORChain. ZachXBT said Alias 4, identified as lolo or Marin, had also participated in laundering funds from the $292 million Kelp DAO exploit earlier in 2026.

Investigators have observed the proceeds moving through cross-chain bridges, asset swaps and privacy tools. AMLBot traced one route from TRX to USDT, across USDT0 to Ethereum, into roughly 145 ETH, through THORChain and finally into about 4.59 BTC.

Approximately four BTC then entered a Wasabi CoinJoin round, where transactions from multiple participants are combined to make attribution more difficult.

Bitget has attributed the operation with high confidence to a DPRK-linked group, citing IP behavior and on-chain signatures, although no independent authority has publicly issued definitive attribution. Mandiant and SlowMist are assisting the investigation, and law enforcement has been notified. Bitget says its protection fund covers the financial impact and customer balances remain intact.

Withdrawals are returning in phases, beginning with Bitcoin on September 28, followed by Ethereum on September 29, USDT on September 30, and other tokens, fiat and peer-to-peer services on October 2.

The exchange says it has remediated the exploited vulnerability and that no further unauthorized transfers are possible, while investigators continue tracing and attempting to freeze the stolen assets.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Bitget Backend Breach Drains $387.5 Million as DPRK-Linked Launderers Expose Themselves appeared first on Cyber Security News.