INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Lazarus Group Suspected in $388M Bitget Hack via Security Flaw

| 2026-09-28 17:42 CRITICAL HIGH VULNERABILITY DISCLOSURE STATE-SPONSORED & ESPIONAGE FRAUD & CRYPTO THEFT
Executive Summary
AI-generated
A critical backend system in Bitget's wallet infrastructure was compromised on September 24, allowing an attacker to spoof transaction data and trigger its approval process. The attack is believed to be the work of North Korean hackers, although the exact perpetrators are still suspected by Bitget CEO Gracy Chen. Approximately $388 million were stolen from Bitget's hot and warm wallets, with no funds compromised in its cold storage system. The attacker exploited a zero-day vulnerability in a third-party security product to gain high-level internal credentials, disguising their activity as routine administrative operations while removing traces of their actions. As a result, Bitget has isolated the affected systems, revoked and reissued internal credentials, turned off the affected functionality, and restricted internal access, with plans to review its assessment and deployment of third-party security products.
Technical Mitigations AI-generated
• Mandiant's threat intelligence platform can detect and analyze the use of legitimate credentials to disguise malicious activity, which was used by the attacker in this case. • The vulnerability exploited by the attackers is a zero-day flaw that has not been patched yet, allowing Bitget to notify the vendor and work on an update. • TRM Labs' blockchain analytics firm can track the stolen funds and identify potential launderings using overlaps between wallets used for earlier North Korean thefts.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

770b10••••••••••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Lazarus GroupLazarus Group
Target & Sectors
DPRK DPRK cryptocurrencycryptocurrency
Incident Timeline
‎2026/09/21
North Korean hackers exploited a security flaw in Bitget's third-party wallet infrastructure to steal $388M.
source_region DPRK
‎September 24
An attacker exploited a security flaw in a third-party product to obtain high-level internal credentials and subsequently stole $388M from Bitget's wallet system.
organisation UTC
‎September 24, 2026
Threat actors exploited a security flaw in a third-party product to steal approximately $388 million from Bitget's hot wallets.
organisation Bitget
organisation UTC
organisation Bitget Hot Wallet Incident
‎September 25
Threat actors exploited a security flaw in a third-party product to steal approximately $388 million from Bitget.
‎2026/09/28
Threat actors disguised their activity as routine administrative operations while removing traces of their actions.
‎2026/09/28
The attacker exploited a vulnerability in a third-party security product to gain unauthorized access and steal approximately $388 million from cryptocurrency exchange Bitget.
threat_actor Lazarus Group
financial $351.6 Hack
organisation Third-Party
organisation Bitget
financial $388 attacker
organisation Customer
organisation Its Protection Fund
organisation Bitget’s
financial $1.4 group
organisation User Protection Fund Expected
organisation User Protection Fund
financial $464 Fund
financial $80,000 group
‎October 2
Bitcoin withdrawals reopened on Monday, and other assets are scheduled to follow in stages through October 2.
Tactical Metrics
Metrics
financial
388,000,000
Financial Impact / Stolen Funds
Metrics
financial
351,600,000
Hack
Metrics
financial
1,400,000,000
Group
Metrics
financial
464,000,000
Fund
Metrics
financial
80,000
Group