
Bitget Hack: $387M Gone, North Korea Suspected
A $387.5M hack at Bitget — the largest crypto breach of 2026 — drained XRP, ETH, and stablecoins, with North Korea's TraderTraitor group suspected.
Key Points
- Attackers drained approximately $387.5 million from Bitget's hot and warm wallets in the early hours of September 25, making it the largest single crypto exchange breach of 2026.
- Elliptic linked the laundering pattern to North Korea's TraderTraitor group, with roughly $83 million in stolen XRP already moved through attacker wallets, and Circle and Tether stepping in to freeze accounts holding approximately $318,000 in stablecoins.
- Bitget's phased withdrawal restart began with Bitcoin at 08:00 UTC today, September 28, with Ethereum and EVM networks following September 29 — but the reputational and market-structure damage extends well beyond one exchange.
$387.5 million is gone from Bitget, and the fingerprints point to Pyongyang. In the early hours of September 25 Beijing time, attackers penetrated Bitget's hot and warm wallet infrastructure, falsified transaction data, bypassed the platform's internal authorization layer, and made off with XRP, ETH, stablecoins, and a basket of other assets in what is now confirmed as the largest crypto exchange hack of 2026. As of Monday morning, three attacker wallets have been nearly emptied and a fourth is still being drained, with approximately $75 million remaining across the original five holding accounts.
How the Attack Worked
This was not a private-key leak — Bitget confirmed that explicitly, and it matters for how the industry interprets the vulnerability. What the attackers did was more sophisticated and more alarming: they compromised a backend wallet management system, injected falsified transaction data into the authorization pipeline, and pushed withdrawals through before the platform's security layer could flag the anomaly. The method suggests either a deep insider threat, an advanced persistent intrusion with prolonged reconnaissance, or both.
Elliptic, the blockchain analytics firm that has tracked North Korean crypto laundering longer than almost anyone in the space, linked the laundering pattern to TraderTraitor — the same group attributed to the $625 million Ronin Network breach in 2022 and multiple subsequent nine-figure heists targeting Asian exchanges and DeFi protocols. The approximately $83 million in stolen XRP that moved through attacker wallets followed a structuring and layering pattern consistent with prior TraderTraitor operations: rapid conversion across multiple chains, use of decentralized exchanges to break the transaction trail, and movement into mixer-adjacent protocols before eventual off-ramping. North Korean attribution has not been formally confirmed by a government body as of Monday morning, but Elliptic's confidence level in the connection is high, and the U.S. Treasury's Office of Foreign Assets Control has been notified.
Circle and Tether responded faster than most observers expected. The two dominant stablecoin issuers blacklisted a wallet holding approximately $318,000 in USDT and USDC — a tiny fraction of the total stolen, but symbolically important as a demonstration that the stablecoin infrastructure can respond in real time to identified theft addresses. The freeze won't recover $387 million, but it sets a precedent for how quickly centralized stablecoin issuers can act when a hack is identified early and attribution is reasonably clear. For regulators watching under the newly enacted GENIUS Act framework, that speed is worth noting — it is exactly the kind of systemic risk management the law was designed to encourage.
The XRP Collateral Damage
XRP gained 7.53% on the week heading into Friday, reached the upper end of its $1.30–$1.60 range, and then ran directly into the Bitget story. The asset closed around $1.57 — still positive on the week, technically — but the late-Friday selling pressure was directly attributable to the news that $83 million in stolen XRP was actively being laundered. When a specific asset is identified as a major component of an active hack and laundering operation, spot holders face a specific and rational risk: that exchanges receiving the tainted XRP will freeze it, creating temporary liquidity disruptions; that the attacker will dump remaining holdings to convert out of XRP into more fungible assets; and that the headline itself will suppress buying interest until the situation is resolved.
The $1.60 resistance level that had been the key technical watch for XRP bulls is now a much harder ceiling to break through in the near term. Sentiment is the variable that technical levels can't fully capture, and the Bitget association has introduced a sentiment overhang on XRP that will take at least several days to clear — assuming no additional wallets surface with stolen XRP and no major exchange announces precautionary XRP freezes. CoinDesk has been tracking the laundering wallet movements in real time, and any new address cluster identified as part of the same operation would extend the damage.
The broader altcoin market took note. Bitget is not a peripheral exchange — it handles significant volume across dozens of assets, and its temporary withdrawal halt created forced holding conditions for users who may have wanted to move assets to cold storage or other platforms immediately after the hack was disclosed. That kind of involuntary exposure amplifies the trust damage beyond the $387.5 million headline figure. Users who couldn't withdraw for 72 hours while watching attacker wallets drain in real time experienced something that no reimbursement promise fully repairs.
What the Industry Watches Next
Bitget's phased withdrawal restart — Bitcoin at 08:00 UTC September 28, Ethereum and EVM networks September 29 — is the immediate operational test. If withdrawals process cleanly and no additional wallet vulnerabilities surface, the platform's damage-containment narrative holds. If there are delays, errors, or a second wave of suspicious outflows, the exchange faces a trust collapse that is very difficult to reverse in a market where competitors are one click away.
The regulatory implications run deeper than Bitget's balance sheet. The Federal Reserve's open comment period on capital and reserve requirements for stablecoin issuers under the GENIUS Act is now receiving a live case study in real-time hack response. The fact that Circle and Tether could freeze wallets within hours, while Bitget's own systems failed to stop $387.5 million from walking out the door, will be exhibit A in arguments for both stricter exchange reserve requirements and expanded stablecoin issuer emergency powers. The CFTC's new guidance allowing futures commission merchants to invest customer funds in tokenized assets — issued just weeks ago — will also face renewed scrutiny, as the question of custody standards for tokenized assets becomes impossible to separate from the Bitget breach.
The SEC's November 11, 2026 deadline on crypto ETF-options decisions is the next major regulatory calendar date, and the Bitget hack guarantees that security infrastructure will be a central question in that review. For traders, the specific levels to watch are Bitget's withdrawal processing speed over the next 48 hours, XRP's ability to hold $1.50 support while the laundering story stays active, and whether any other major exchange announces precautionary measures that signal concern about similar backend vulnerabilities in their own systems. The $75 million still sitting across the original attacker wallets is not static — it will move, and when it does, the chain analytics community will be watching every hop.
The Weekly Investor
Daily market analysis for active traders. Free.


