The first detailed on-chain reconstruction of the Bitget breach shows the stolen funds were split into fresh wallets holding round amounts within hours of the theft, and that the laundering infrastructure overlaps with wallets used to process two earlier thefts attributed to North Korea's TraderTraitor actors. TRM Labs, which published the analysis on September 25, stresses it has not definitively attributed the attack — but the overlaps point in one direction.
Bitget has reported $351.6 million moved out of its hot and warm wallets on September 24 across Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain and Base, detected at 18:31 UTC. Early public estimates of $170–190 million covered only the EVM chains; TRM's data shows roughly $158 million in XRP and $7 million in TRX also left the exchange, bringing observed outflows close to Bitget's reported figure. It is the largest crypto theft of 2026 by value so far, per TRM Labs.
No Stolen Keys — Spoofed Authorizations
Bitget says the attacker compromised a backend system connected to its wallet infrastructure, manipulated the transaction data shown to its authorization process, and induced it to approve the transfers. The exchange maintains its private keys were not stolen and cold wallets were untouched.
That mechanism echoes the February 2025 Bybit theft, in which signers approved a malicious interface-rendered transaction without any key material being compromised, as TRM notes. The pattern — attack the information used to authorize a transfer rather than the key itself — has now produced two of the largest exchange thefts on record.
Round Numbers, Then Silence
The proceeds were divided with unusual discipline. On Ethereum, much of the value passed through a single aggregator address that also received funds on five other chains; a second wallet distributed its balance over roughly two hours into newly created wallets holding approximately 10,000 ETH each. Eight wallets ended up holding most of the stolen ETH. The XRP followed the same shape, arriving in accounts holding round amounts of 20 million XRP. As of the morning of September 25, most of those funds had not moved again — a dormancy pattern TRM describes as typical of recent North Korean heists, including Bybit and the Drift Protocol theft.
The share that did move converted into Bitcoin. Funds on BNB Chain and Ethereum were swapped through THORChain and split across Bitcoin addresses in peel chains; on TRON, stolen TRX was swapped for USDT on SunSwap, bridged to Ethereum via USDT0, and fed into the same THORChain route. Smaller amounts passed through Across, Bridgers, Chainflip and FixedFloat. TRM has tagged the addresses as "Bitget Exploiter September 2026."
Why North Korea Is Suspected, Not Confirmed
Bitget CEO Gracy Chen has described North Korean involvement as "very likely," citing IP addresses linked to VPN services associated with a North Korean hacking group. TRM goes further on structure but stops short of attribution: on-chain tracing shows multiple overlaps between the wallets laundering the Bitget proceeds and those used to launder the Bybit and AFX Bridge thefts, through a laundering network TRM says it has never observed working with any other group. Those links, TRM assesses, point toward TraderTraitor — but the firm notes the same swap services and techniques are technically available to other actors and expects harder evidence to emerge in the coming days.
Elliptic, which counts the Bitget loss at $357 million by its own methodology, likewise assesses the hack as likely carried out by North Korea-linked actors, Bloomberg reported.
Stablecoin Freezers Move First
Circle and Tether froze a Bitget exploiter wallet holding about $318,000 in stablecoins, CoinDesk reported — a small fraction of the total, but the fastest containment lever available. Bitget says some blockchain foundations have frozen hacker wallets, withdrawals remain suspended, and its $464 million User Protection Fund covers the loss. Mandiant and SlowMist are supporting the investigation alongside law enforcement.
The open question is the dormant majority. After Bybit, the converted bitcoin sat largely stationary before the next laundering stage through mixers and over-the-counter desks. If Bitget follows the same playbook, the round-number wallets now parked on Ethereum and the XRP Ledger are the last readable checkpoint before the trail gets expensive to follow.
TrustGrade tracks exchange security posture and incident history. Verified trust data: trustgrade.ai.