toobit
Buy crypto
Buy cryptoThe fastest path to your first trade
P2P tradingTrade at the best prices with multiple local payment options
Bank cardPay with Visa or Mastercard
Third-partyPay via MoonPay, Advcash, Simplex, and more
DepositTransfer from another wallet
Toobit CardPay with crypto wherever you go.
Markets
OpportunitiesTrack market sentiment and top movers
OverviewReal-time prices for all trading pairs
Futures
USDT-M PerpetualContracts settled in USDT
USDC-M PerpetualContracts settled in USDC
Event ContractsTrade on the outcome of market events
Prediction MarketTurn insights into value
Lite PerpetualSimple contracts made for easy trading
Demo TradingPractice trading in a risk-free environment
Trading BotsAutomated grid and DCA strategies
TradFi
Trading
SpotBuy and sell cryptocurrencies
DEX +Trade popular on-chain Web3 tokens in seconds
LaunchpadAccess early-stage token listings
ConvertZero-fee instant asset swaps
API TradingAutomate trading strategies with custom scripts and apps
Toobit SynapseMarket insights driven by AI analysis
Toobit x TradingViewTrade directly from TradingView charts
Agent Trade KitEquip AI agents with trading and account skills
Rewards
Copy
Follow Lead TradersCopy trades from top-performing profiles
To be a Lead TraderShare your trades and earn commissions
More
Finance
EarnPut your idle assets to work
Partnerships
Broker ProgramMonetize API volume and trading infrastructure
Ambassador ProgramRepresent the exchange and earn monthly incentives
Toobit x Nova.MemeLaunch and trade memecoins with instant liquidity
Learn
AcademyTechnical analysis and crypto trading guides
Support CenterSelf-service help and 24/7 technical assistance
Announcement CenterLatest listings, campaigns, and official product news
NewsBreaking crypto news and market moves
BlogMarket insights and exchange updates
Explore
Toobit VIP ProgramEnjoy fee discounts and many exclusive rewards.
InsightsStay updated on the latest crypto news
Toobit CommunityConnect with The Hive, our global community of traders
3 years togetherCelebrate our journey and the community that built it
About usThe story behind the award-winning exchange
Suggestions & FeedbackShare your ideas to improve the exchange
Proof of ReservesTrust built on 100% reserves
Log in
Sign up
🔥BTC/USDT
Scan to download
iOS or Android app
More download options

Bitget hack suggests North Korea link

2026-10-01 04:18

Bitget said abnormal transfers from its hot and warm wallets on Sept. 24 resulted in $387.5 million being moved, revising an initial loss estimate of about $351.6 million. Blockchain security firms TRM Labs and Elliptic have identified laundering patterns that resemble activity in earlier North Korea-linked cryptocurrency attacks, though a final public attribution for the Bitget incident has not been announced.

The case has quickly renewed scrutiny of the network commonly referred to as Lazarus Group, a broad label applied to multiple North Korea-aligned cyber operations rather than one clearly defined hacking unit. If investigators connect the Bitget theft to that apparatus, publicly cited estimates would place cumulative North Korea-linked crypto theft near $7.8 billion through September 2026.

TRM Labs said portions of the stolen assets moved along routes used in previous attacks attributed to North Korean actors, including the 2025 Bybit theft and the AFX Bridge exploit. Elliptic assessed a North Korean connection as “highly likely.”

Funds moved through bridges, swaps and bitcoin wallets

The movement of Bitget-linked assets followed a familiar chain-hopping pattern designed to fragment the trail across networks and assets. TRM Labs observed funds moving from BNB Chain and Ethereum through THORChain, a cross-chain swap protocol, into Bitcoin before being divided among multiple new Bitcoin addresses.

Other routes included TRON-based TRX converted into USDT through SunSwap, bridged to Ethereum, and sent through a similar THORChain path, according to TRM Labs. The firm also identified activity involving Across, Chainflip and FixedFloat. Assets held on Arbitrum were bridged to Ethereum, while stablecoins and non-native tokens were converted into native chain assets before further transfers.

Some newly created wallets held roughly 10,000 ETH or 20 million XRP, the on-chain tracing showed. Breaking funds into clusters of large but separate holdings can complicate recovery work while allowing operators to shift assets through different services in parallel.

The approach mirrors the laundering that followed the February 2025 Bybit breach, in which roughly $1.5 billion in crypto was stolen. TRM Labs reported that at least $160 million had entered laundering channels within 48 hours of that attack, rising above $400 million by Feb. 26. By March 3, most of the stolen ETH had been shifted to new addresses and largely converted into Bitcoin through services including THORChain.

Chainalysis has previously documented similar scale in the 2022 Ronin Bridge theft, where Lazarus-linked operators used more than 12,000 addresses. After the U.S. Treasury sanctioned the privacy protocol Tornado Cash, the firm said North Korean laundering operations increased their use of bridges and decentralized finance services to move value between blockchains.

A theft record measured in billions

Chainalysis estimated that North Korea-linked hackers stole at least $6.75 billion in cryptocurrency through the end of 2025, including about $2.02 billion during 2025 alone. The total includes incidents of varying confidence levels and reflects an ecosystem extending beyond attacks directly confirmed by law enforcement.

A narrower tally of cases publicly attributed by governments or law-enforcement agencies and paired with confirmed loss figures exceeds $3.1 billion. Among the largest were the $620 million Ronin Bridge theft in March 2022 and the $1.5 billion Bybit breach in February 2025.

The FBI attributed Ronin to Lazarus Group and APT38 in April 2022. It attributed the Harmony Horizon Bridge theft, worth about $100 million, to Lazarus Group in January 2023, later describing the movement of more than $60 million in ETH through RAILGUN and conversions to Bitcoin. The agency also attributed the September 2023 theft of about $41 million from Stake to Lazarus.

In May 2024, DMM Bitcoin lost 4,502.9 BTC, worth about $308 million at the time. The FBI and Japan’s National Police Agency later attributed the operation to TraderTraitor, a crypto-focused cluster that researchers have tied to the North Korean state cyber apparatus. Authorities said attackers posed as recruiters, sent a malicious Python script disguised as a hiring test to an employee of wallet firm Ginco, and used a stolen session cookie to gain access to internal communications.

The FBI linked TraderTraitor to the Bybit breach five days after the attack, as well as earlier thefts involving Atomic Wallet, Alphapo and CoinsPaid.

Different names describe overlapping operations

The public terminology around these operations can obscure how closely related they appear to be. In 2019, the U.S. Treasury sanctioned Lazarus Group, BlueNoroff and Andariel, stating that all three were controlled by North Korea’s Reconnaissance General Bureau, or RGB.

Security companies use separate naming systems based on their own threat-tracking models. Microsoft has linked Diamond Sleet to Lazarus, ZINC and LABYRINTH CHOLLIMA, while associating Sapphire Sleet with BlueNoroff, CryptoCore, UNC1069 and STARDUST CHOLLIMA. Mandiant has used APT38 for financially motivated activity and has tracked crypto-oriented campaigns under names including CryptoCore, TraderTraitor and UNC4736.

BlueNoroff, active by about 2014, initially targeted banks and the SWIFT financial messaging system. The U.S. Treasury said the group had attempted thefts totaling more than $1.1 billion from financial institutions by 2018. Its methods later became closely associated with the crypto sector, where fake recruitment approaches, Telegram messages, counterfeit meeting software and malicious coding assignments have targeted exchange employees, developers and wallet infrastructure providers.

Microsoft said npm supply-chain attacks during 2026 involving Axios and Mastra were linked to BlueNoroff. The Mastra incident affected more than 140 npm packages, according to Microsoft, creating a route to steal credentials, tokens and development access from compromised installations.

Other clusters perform different functions. Citrine Sleet, also tracked as AppleJeus and UNC4736, has been associated with malicious crypto-trading applications and malware delivery. Andariel, also known as Onyx Sleet and APT45, has focused more heavily on defense, energy, government and nuclear-related targets, according to U.S. sanctions records and Microsoft research.

CrowdStrike uses the name Famous Chollima for North Korea-linked remote IT-worker operations. The firm said the network infiltrated more than 320 companies in the 12 months to 2025, up about 220% year over year. U.S. court filings have described workers using false identities and remote-work arrangements, with wages sometimes paid in USDC or USDT before being routed onward.

Exchange security moves beyond wallet keys

The Bitget case places attention on the systems that authorize withdrawals rather than only the cryptographic keys that control cold wallets. The supplied account of the incident says intruders compromised a production job server and forged withdrawal approvals while cold-storage keys remained untouched.

That type of intrusion aligns with a pattern seen in several major thefts: attackers increasingly seek access to employee sessions, internal messaging, software dependencies and approval workflows. These entry points can give an intruder a way to make fraudulent activity appear operationally legitimate inside a platform.

Chainalysis’ estimate that protocol logic losses fell 74% between 2022 and 2025, while total digital-asset theft remained above $2.17 billion in 2025, illustrates the changing target set. Large centralized systems, their vendors and their workforce now offer attackers paths to funds that do not require finding a vulnerability in an on-chain smart contract.

For exchanges and wallet providers, that shifts security pressure toward segregated approval systems, hardened software supply chains, monitoring of privileged sessions and procedures that can detect suspicious withdrawal behavior before funds cross multiple chains. The rapid dispersal reported in the Bitget case shows how little time remains once a high-value withdrawal process has been compromised.


Concerned about exchange hacks? Learn key protection steps in crypto safety standards every trader should know before your next transfer.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

About
About us
Terms of Use
Privacy Policy
Risk disclosure
Toobit Community
Announcement Center
Security solutions
Toobit Shield
Proof of Reserves
Services
Trading
Futures
Copy
Affiliate Program
API
Listing application
Bug bounty
Toobit Card
Support
Support Center
Academy
Referral
Fee rate policy
Official verification
Network monitoring
Suggestions & Feedback
Buy crypto
Buy Bitcoin
Buy Ethereum
Buy Dogecoin
Buy TON
Buy SOL
Buy XRP
Contact
Customer Support
support@toobit.com
Business
listing@toobit.com
Overview
market@toobit.com
Legal
legal@toobit.com
Apps
Google Play
App Store
Android APK
Community
TwitterMediumYoutubeDiscordRedditFacebookCoinMarketCapCoinCodexCoinGeckoLinkedinQuoraThreads
Download app
Warning

© 2026 Toobit.com. All rights reserved.