Observed Signal · Sep 25, 2026 · Security Breach · Source: Trending Topics (DACH/CEE Innovation & Tech) · Impact: 3/5 · Sentiment: Negative
Bitget Loses $352 Million in Hack, CEO Suspects North Korea
Cryptocurrency exchange Bitget reported a hack involving unauthorized transfers from its hot and warm wallets, totaling approximately $351.6 million. CEO Gracy Chen suspects North Korean hackers based on IP address analysis, though attribution is not fully confirmed. The attackers breached a central backend system, forged transfer details, and initiated the exchange's authorized signature process without compromising private keys. Bitget has suspended withdrawals but trading continues, and its cold wallets remain unaffected. The company's Protection Fund, exceeding $465 million, is intended to cover the loss, supplemented by over $1 billion in equity. This incident echoes the February 2025 Bybit hack, also attributed to North Korean actors, which involved a compromised Safe{Wallet} developer machine and resulted in a $1.5 billion theft. Bitget had previously lent Bybit 40,000 ETH to help it recover from that attack.
Significant crypto exchange hack impacting user trust and industry security, but not directly related to core AdTech/MarTech.
Track Bybit Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Bitget lost approximately $351.6 million in unauthorized transfers from hot and warm wallets.
- CEO Gracy Chen suggested North Korean hackers based on IP address patterns, but attribution is not fully confirmed.
- Attackers forged transfer details in a central backend system without compromising private keys.
- Bitget has suspended withdrawals but trading continues; the Protection Fund holds over $465 million, more than covering the loss.
- The incident follows the Bybit hack of February 2025, attributed to North Korea, where attackers compromised Safe{Wallet} to steal $1.5 billion in ETH.
Connected Companies & Entities
2 Entities mapped“Bitget lent Bybit 40,000 Ether after Bybit's hack....”
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Bitcoin Sidechain Liquid Network Hit by $320M Exploit
The Liquid Network, a Bitcoin sidechain operated by Blockstream, suffered a significant security breach in which attackers stole approximately 4,000 BTC (worth around $320 million) by exploiting a software vulnerability that allowed the exchange of unbacked L-BTC. The attackers, claiming to be white-hat hackers, offered to return most of the funds if Blockstream patched the bug. After the patch was applied, around 3,400 BTC were returned to the network's wallet, while about 598.5 BTC (worth ~$47 million) remained in the hackers' possession, possibly as an unplanned bug bounty. The vulnerability was traced to a caching flaw in Blockstream's Elements software, specifically in the Confidential Transactions validation process, which allowed counterfeit token creation. The federation's multisig and PAK mechanisms were not compromised. The network remains paused while security enhancements are implemented before a safe restart.
North Korea behind nearly half of US tech hacks
CrowdStrike's 2026 Technology Threat Landscape report finds North Korean hackers, operating under the group name 'Famous Chollima,' were responsible for roughly 47% of documented state-backed 'hands-on-keyboard' intrusions targeting U.S. tech companies between April 2025 and May 2026. The group commonly poses as remote IT workers, developers or recruiters using stolen credentials, real-time deepfake images and fraudulent identity documents to gain jobs and persistent access. Operators steal intellectual property and cryptocurrency — often funneling salaries and stolen funds back to the Kim regime — and sometimes extort companies with threatened disclosures. The report highlights targeting of blockchain developers and ongoing use of these operations to finance Pyongyang’s prohibited weapons programs.
North Korean Hackers Infiltrate Western Firms as Fake Developers
U.S. authorities have sanctioned six individuals and two organisations accused of placing North Korean IT workers as fake developers into Western companies. According to U.S. agencies, these embedded workers earned about $800 million in wages in 2024, funds allegedly directed to Pyongyang’s weapons programmes; in the same period North Korea reportedly stole about $2 billion in cryptocurrencies. The campaign — observed in Europe and involving intermediaries operating from Spain and a shell company in Vietnam — included theft of source code, transfer of code repositories to private accounts, deployment of malware and later extortion of employers. Google Threat Intelligence Group noted increased applications from North Korean IT candidates in Europe. The FBI has advised companies to conduct in-person interviews, restrict new hires’ access, monitor network and remote connections, and vet external recruiters.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
