What happened
Bitget CEO Gracy Chen told BeInCrypto that North Korean hackers were 'very likely' responsible for the $350 million theft that struck the exchange on Wednesday, September 24. Chen said the attackers breached a backend system, not the cold storage layer, and never obtained private keys tied to customer funds. She pointed to a VPN trail her security team followed as the primary basis for the attribution.
The exchange suspended withdrawals shortly after the breach was detected and has not restored them. That freeze is still in place as of Thursday morning in Singapore, where Bitget's operational headquarters sits. DefiLlama's hack tracker now lists the September 24 breach as the largest crypto exploit of 2026, edging past the string of DeFi bridge losses recorded earlier in the year.
Why it matters
North Korea attribution changes the conversation. Lazarus Group and its adjacent units have drained more than $3 billion from crypto platforms since 2022, per prior Chainalysis and TRM Labs reporting, and their playbook favors backend compromises and social engineering over on-chain exploits. A confirmed DPRK link on a top-10 exchange tightens the argument US and Korean regulators have been making all year about custody controls and sanctions screening.
Bitget is a centralized venue with roughly $8 billion in reported spot volume on a typical day and a large derivatives book. A prolonged withdrawal freeze on that scale of exchange doesn't stay contained to one order book. It bleeds into perp funding, into stablecoin flows on Tron and Ethereum, and into the counterparty conversations market makers have every morning.
