What happened
Chainalysis published an attribution report on Friday tying the September 24 breach of Bitget to North Korean state-linked actors, per Decrypt's write-up of the firm's findings. The exploit drained roughly $387 million from hot-wallet infrastructure, and the stolen assets were fragmented across four blockchains within the first few hours. The firm said its investigators leaned on a proprietary AI tracing layer that clusters addresses and flags bridge hops in near real time, letting analysts stay a step behind rather than days behind the attackers. It's the kind of post-incident tempo that has been missing from most prior DPRK attributions, which typically landed weeks after the fact.
Bitget confirmed the breach the same day it happened. The exchange said customer funds were covered from its reserve pool. Chainalysis didn't name specific wallet clusters in the public note Decrypt cited, but it flagged that laundering patterns matched Lazarus Group playbooks seen in the Ronin, Harmony, and WazirX cases.
Why it matters
The $387 million figure is big on its own. The bigger number is what it unlocks: Chainalysis now puts North Korea's 2026 crypto theft total above $1 billion, confirmed, with a quarter of the year still to run. That's on pace to eclipse 2024's roughly $1.3 billion attribution and reset expectations for how much a single state actor can extract from the sector in a calendar year.
The speed of attribution matters as much as the dollar count. Faster tracing means faster sanctions designations, faster exchange freeze requests, and a narrower window for stolen funds to reach OTC desks or P2P venues that will actually swap them for fiat. The Treasury's Office of Foreign Assets Control has leaned harder on Tornado Cash successors and Chinese OTC rings in the past year, and attribution of this size will give it fresh material to work with.
