Elliptic, a blockchain analytics firm, said the crypto exchangeBitget attack shares characteristics with previous incidents attributed to North Korean groups. Investigators found similarities in the movement and laundering of stolen assets, along with on-chain connections to addresses associated with earlier attacks.
A $357 mn hack of Bitget was likely carried out by North Korea-linked hackers, pushing DPRK-attributed digital asset theft above $1 bn this year.
Some funds were linked to addresses connected with previous crypto thefts, including the $1.5bn Bybit attack in 2025. Elliptic said early laundering patterns and on-chain overlaps point toward TraderTraitor, a North Korea-linked group associated with previous crypto exchange attacks.
Elliptic has tracked more than 50 security incidents associated with North Korea during 2026, representing around $1.2bn in stolen digital assets. The Bitget breach pushed its total estimate for DPRK-linked crypto theft this year past $1bn.
North Korean groups have stolen billions of dollars in cryptocurrency since 2017, with digital asset theft becoming an important source of revenue for the sanctions-hit country.
Crypto exchanges remain attractive targets because large amounts of digital assets sit in connected wallet infrastructure and stolen funds move quickly between networks.
Bitget suspends withdrawals after unauthorized transfers
Bitget detected unauthorized transfers from its wallets on Sept. 24 involving several cryptocurrencies. The attackers drained assets from hot and warm wallets before swapping many of the stolen tokens and moving them across multiple blockchain networks.
The exchange suspended withdrawals after identifying the breach. Bitget said its cold-storage wallets remained unaffected, while customer account balances stayed intact.
CEO Gracy Chen said the attack was consistent with methods previously associated with North Korean hacking groups. Bitget’s $464 mn User Protection Fund is sufficient to cover the stolen assets, she said.
Bitget has brought in cybersecurity firms Mandiant and SlowMist to investigate the incident. The companies are examining the source of the breach and tracing movement of the stolen assets while the exchange reviews its security systems.
North Korea link based on laundering and on-chain evidence
Elliptic’s assessment rests partly on how the stolen cryptocurrency was handled after leaving Bitget. The attackers rapidly exchanged assets and transferred funds between networks, behaviour the analytics firm said resembles previous DPRK-linked operations.
Investigators also identified infrastructure and blockchain overlaps with earlier attacks attributed to North Korean hackers. These connections led Elliptic to assess the North Korea link as highly likely rather than confirmed.
The Bitget theft follows several large crypto breaches during 2026. Artificial intelligence is giving cybercriminals additional tools for reconnaissance and attack preparation, while crypto businesses continue to hold large pools of assets accessible through online infrastructure.
For Bitget, the immediate financial loss is covered by its protection fund, according to the company. The investigation now centres on how the attackers gained access, where the stolen assets moved and whether more funds are recoverable.









