Back to all incidents

Bitget

bitget.com
CONFIRMED

Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million. [...]

Observable Status CONFIRMED
Industry / Sector Technology & Commercial
Incident Classification Network Intrusion & Data Exfiltration
Attributed Threat Actor Unknown / Unattributed
Affected Population Scope Under Audit
First Seen 2026-09-25
Last Updated 2026-10-01
Personal Identifiable Information (PII) Corporate Contact Records
OPEN WEIGHTS TELEMETRY • DETERMINISTIC CONFIDENCE

Confidence & Source Corroboration

74% CONFIDENCE
1. Primary Authority CONFIRMED BY TARGET Base weight: 50%
2. Evidence Specificity +7% Domain & Scope Telemetry
3. Corroboration Curve +12% 2 independent domains
4. Timeline & Staleness +5% 5 milestones logged
Corroborated Source Domains:
bleepingcomputer.com thehackernews.com

Technical Forensic Briefing

Incident Overview

The Bitget cybersecurity event represents a confirmed Network Intrusion & Data Exfiltration within the Technology & Commercial sector, attributed to the Unknown / Unattributed cyber threat collective. Discovered through technical indicators and regulatory breach filings, the event resulted in unauthorized access to sensitive internal IT environments, with the exact population scope undergoing regulatory audit.

Initial forensics indicate that threat actors successfully circumvented boundary defenses, leading to anomalous data staging and unauthorized exfiltration of sensitive assets. Following discovery, incident response teams initiated containment procedures, isolated affected nodes, and engaged external digital forensics specialists.

Compromised Assets & Data Scope

Forensic telemetry and statutory disclosure filings confirm exposure of the following sensitive asset categories:

  • Primary Data Classes: Personal Identifiable Information (PII), Corporate Contact Records.
  • Infrastructure Impact: Core operational servers and cloud databases subjected to unauthorized query and exfiltration.
  • Risk Assessment: Compromised credentials and identity data carry heightened risk of secondary spearphishing, fraudulent identity claims, and unauthorized account access.

Statutory Disclosures & Compliance

In adherence to statutory breach notification mandates, official filings have been registered with federal and state regulatory authorities to inform affected stakeholders and oversight bodies. Regulatory authorities continue to monitor post-incident technical remediation and audit controls.

Milestone Timeline (5 events logged)

2026-09-28 09:25 UTC
INDEPENDENT VERIFICATION

Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist

2026-09-28 17:42 UTC
INDEPENDENT VERIFICATION

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

2026-09-25 10:35 UTC
INDEPENDENT VERIFICATION

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

2026-09-30 11:11 UTC
INDEPENDENT VERIFICATION

Bitget hacked via zero-day in third-party security products

2026-10-01 05:21 UTC
CONFIRMED BY TARGET

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

Have updated information or a new verifiable source?

This incident record is a flat Markdown file tracked in Git. Propose an update or add a milestone via Pull Request.

Propose Update via GitHub