INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Lazarus Group Suspected in $388M Bitget Hack via Security Flaw
| 2026-09-28 17:42 CRITICAL HIGH VULNERABILITY DISCLOSURE STATE-SPONSORED & ESPIONAGE FRAUD & CRYPTO THEFT
Executive Summary
AI-generated
A critical backend system in Bitget's wallet infrastructure was compromised on September 24, allowing an attacker to spoof transaction data and trigger its approval process. The attack is believed to be the work of North Korean hackers, although the exact perpetrators are still suspected by Bitget CEO Gracy Chen. Approximately $388 million were stolen from Bitget's hot and warm wallets, with no funds compromised in its cold storage system. The attacker exploited a zero-day vulnerability in a third-party security product to gain high-level internal credentials, disguising their activity as routine administrative operations while removing traces of their actions. As a result, Bitget has isolated the affected systems, revoked and reissued internal credentials, turned off the affected functionality, and restricted internal access, with plans to review its assessment and deployment of third-party security products.
Technical Mitigations AI-generated
• Mandiant's threat intelligence platform can detect and analyze the use of legitimate credentials to disguise malicious activity, which was used by the attacker in this case.
• The vulnerability exploited by the attackers is a zero-day flaw that has not been patched yet, allowing Bitget to notify the vendor and work on an update.
• TRM Labs' blockchain analytics firm can track the stolen funds and identify potential launderings using overlaps between wallets used for earlier North Korean thefts.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
770b10••••••••••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Lazarus GroupLazarus Group
Target & Sectors
DPRK
DPRK
cryptocurrencycryptocurrency
Incident Timeline
2026/09/21
North Korean hackers exploited a security flaw in Bitget's third-party wallet infrastructure to steal $388M.
Click on any entity below to view its context and source!
source_region
DPRK
Bitget, which last week pointed to North Korean hackers, still suspects "the same group of people," Chen told The Block.
TRM Labs
, a blockchain analytics firm, said last week that it found overlaps between the stolen funds and wallets used to launder earlier North Korean thefts.
September 24
An attacker exploited a security flaw in a third-party product to obtain high-level internal credentials and subsequently stole $388M from Bitget's wallet system.
Click on any entity below to view its context and source!
organisation
UTC
On September 24, the attacker first made two small test transfers at 18:31 UTC.
September 24, 2026
Threat actors exploited a security flaw in a third-party product to steal approximately $388 million from Bitget's hot wallets.
Click on any entity below to view its context and source!
organisation
Bitget
The incident was detected at 18:31 UTC on September 24, 2026, when Bitget’s security systems identified unauthorized transfers involving several hot wallets.
organisation
UTC
The incident was detected at 18:31 UTC on September 24, 2026, when Bitget’s security systems identified unauthorized transfers involving several hot wallets.
organisation
Bitget Hot Wallet Incident
Bitget Hot Wallet Incident — September 24, 2026
September 25
Threat actors exploited a security flaw in a third-party product to steal approximately $388 million from Bitget.
2026/09/28
Threat actors disguised their activity as routine administrative operations while removing traces of their actions.
2026/09/28
The attacker exploited a vulnerability in a third-party security product to gain unauthorized access and steal approximately $388 million from cryptocurrency exchange Bitget.
Click on any entity below to view its context and source!
threat_actor
Lazarus Group
financial
$351.6 Hack
organisation
Third-Party
Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M.
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday.
organisation
Bitget
Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M.
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday.
financial
$388 attacker
Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M.
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday.
organisation
Customer
Customer account balances were not affected, the exchange says.
organisation
Its Protection Fund
Its Protection Fund, a reserve set aside for security incidents like this one, will cover the loss.
organisation
Bitget’s
Bitget Says Its Internal Systems Were Breached
During a
live broadcast on X
, Chen described the incident as a direct breach of Bitget’s systems or servers.
financial
$1.4 group
Lazarus has previously been blamed for major cryptocurrency thefts, including attacks against centralized exchanges such as the Bybit hack in 2025, in which the group stole $1.4 billion, blockchain services and individual cryptocurrency holders.
organisation
User Protection Fund Expected
User Protection Fund Expected to Cover Loss
Bitget says its User Protection Fund is large enough to cover the entire reported loss.
organisation
User Protection Fund
User Protection Fund Expected to Cover Loss
Bitget says its User Protection Fund is large enough to cover the entire reported loss.
financial
$464 Fund
According to
Bitget CEO Gracy Chen
, the stolen amount is covered by the exchange’s User Protection Fund, which held more than $464 million when the incident occurred.
financial
$80,000 group
Chen said she had encountered the group before when approximately $80,000 was stolen from one of her personal wallets outside Bitget.
October 2
Bitcoin withdrawals reopened on Monday, and other assets are scheduled to follow in stages through October 2.
Tactical Metrics
Metrics
financial
388,000,000
Financial Impact / Stolen Funds
Click for context!
Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M.
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday.
Metrics
Metrics
financial
1,400,000,000
Group
Lazarus has previously been blamed for major cryptocurrency thefts, including attacks against centralized exchanges such as the Bybit hack in 2025, in which the group stole $1.4 billion, blockchain services and individual cryptocurrency holders.
Metrics
financial
464,000,000
Fund
According to
Bitget CEO Gracy Chen
, the stolen amount is covered by the exchange’s User Protection Fund, which held more than $464 million when the incident occurred.
Metrics
financial
80,000
Group
Chen said she had encountered the group before when approximately $80,000 was stolen from one of her personal wallets outside Bitget.
Intelligence Sources
The Hacker News
2026-09-28
HackRead
2026-09-25
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T11:11
Comprehensive Tactical Telemetry
Highly Correlated Entities
9x
organisation
Identified Entity
Third-Party
entity
7x
timeline
Temporal Reference
2026/09/21
date
2x
financial
Group
1,400,000,000
group
Contextual Telemetry
Context Block
11 METRICS
source region
Origin Region
DPRK
region
target region
Target Region
DPRK
region
financial
Financial Impact / Stolen Funds
388,000,000
attacker
general metric
Minutes
30
minutes
source region
Origin Country
Korea, Democratic People's Republic of
country
threat actor
APT Group
Lazarus Group
actor
financial
Hack
351,600,000
hack
target region
Target Country
Korea, Democratic People's Republic of
country
financial
Fund
464,000,000
fund
general metric
People
2,000
people
general metric
Hours
24
hours
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.