MD
Mathew Di Salvo
September 28, 2026 · 2 min read
Signals

North Korean Hackers Linked to $388 Million Bitget Crypto Exchange Theft: CEO

North Korean Hackers Linked to $388 Million Bitget Crypto Exchange Theft: CEO

Di Salvo admitted that response protocols were too slow, saying

Bitget, a major cryptocurrency exchange, confirmed on Thursday that hackers traced to North Korea stole $388 million in digital assets during a cyberattack. The breach occurred on September 25, 2026, targeting the platform’s hot wallets. CEO Mathew Di Salvo disclosed the incident publicly, stating that forensic analysis pointed to state-backed actors from the Democratic People’s Republic of Korea. The attackers exploited a vulnerability in Bitget’s multi-signature wallet system, allowing unauthorized transfers of Bitcoin, Ethereum, and stablecoins. Security firms assisting the investigation noted similarities to past Lazarus Group operations, including use of mixing services and rapid fund dispersal. Bitget has since frozen affected accounts and is working with blockchain analysts to trace the stolen funds. How the Breach Went Undetected Despite real-time monitoring systems, the theft remained unnoticed for over three hours due to delayed anomaly alerts. Internal logs show the hackers mimicked legitimate withdrawal patterns, evading initial fraud detection.

Di Salvo admitted that response protocols were too slow, saying, „We underestimated the sophistication of the attack vectors used.” The exchange has since upgraded its monitoring thresholds and added behavioral AI layers to its security stack. What Steps Are Users Taking Now? Following the announcement, thousands of Bitget users withdrew funds amid fears of further instability. Trading volume dropped nearly 40% in the 24 hours after the news broke, according to market data. Some users have filed complaints with financial regulators, demanding compensation and greater transparency. Bitget has pledged to cover losses from its insurance fund, though full reimbursement may take weeks. Frequently Asked Questions Was customer data compromised in the hack? No, Bitget confirmed that no personal information or KYC data was accessed during the breach. Only digital assets held in hot wallets were affected. Is Bitget still operating normally?

Yes, the exchange resumed normal trading and withdrawal services within 12 hours of identifying the breach. Enhanced security measures are now in place. Will users get their stolen funds back? Bitget has committed to using its reserve fund to cover user losses, but recovery of the actual stolen cryptocurrency depends on ongoing blockchain tracing efforts.

More stories:

Content written by Mathew Di Salvo for ai-trading-guru.com editorial team, AI-assisted.

Share:

Leave a comment