Home › Intelligence › Brief
BREACH BRIEF 🔴 Critical Breach

North Korean Hackers Steal $351.6 M from Bitget Crypto Exchange via Backend Compromise

Bitget reported that suspected North Korean threat actors exploited a backend vulnerability, moving $351.6 million from hot and warm wallets on 24 Sept 2026. The loss underscores the need for strong privileged‑access controls and continuous audit evidence for financial‑services platforms.

Verisq™ Intelligence · 📅 September 25, 2026 · 📰 thehackernews.com
🔴
Severity
Critical
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
thehackernews.com

North Korean Hackers Steal $351.6 M from Bitget Crypto Exchange via Backend Compromise

What Happened – On 24 Sept 2026 Bitget detected unauthorized transfers from a limited set of hot and warm wallets. Investigations attribute the breach to suspected North Korean threat actors who exploited a backend vulnerability, resulting in the theft of roughly $351.6 million.

Why It Matters for Trust & Control Assurance

  • The incident illustrates the risk of inadequate privileged‑access controls over high‑value assets – a core scenario that continuous control‑assurance programs are built to detect and evidence.
  • Real‑time monitoring of privileged actions and immutable audit trails are essential to prove due‑diligence and to respond defensibly during a forensic investigation.
  • Demonstrating robust access‑control governance helps satisfy multiple framework objectives (e.g., NIST CSF Identify & Protect, ISO 27001 Access Control) with a single control evidence set.

Who Is Affected – Cryptocurrency exchanges and other financial‑services platforms that manage hot‑wallet assets.

Recommended Actions

  • Conduct an immediate privileged‑access review of all backend services and enforce least‑privilege principles.
  • Deploy multi‑factor authentication and session‑recording for any accounts that can initiate wallet transfers.
  • Implement continuous transaction monitoring with tamper‑evident logging to create a defensible audit trail.
  • Segment hot‑wallet infrastructure from broader services and apply strict network‑level controls.
  • Collect and retain evidence of these controls for audit readiness and potential regulatory inquiries.

Source: The Hacker News

Technical Notes – The breach stemmed from a backend compromise (likely a vulnerability exploit) that gave attackers the ability to initiate transfers from hot/warm wallets. No cold‑wallet assets were reported stolen.

📰 Original Source
https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html ↗

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →