North Korean Hackers Steal $351.6 M from Bitget Crypto Exchange via Backend Compromise
What Happened – On 24 Sept 2026 Bitget detected unauthorized transfers from a limited set of hot and warm wallets. Investigations attribute the breach to suspected North Korean threat actors who exploited a backend vulnerability, resulting in the theft of roughly $351.6 million.
Why It Matters for Trust & Control Assurance
- The incident illustrates the risk of inadequate privileged‑access controls over high‑value assets – a core scenario that continuous control‑assurance programs are built to detect and evidence.
- Real‑time monitoring of privileged actions and immutable audit trails are essential to prove due‑diligence and to respond defensibly during a forensic investigation.
- Demonstrating robust access‑control governance helps satisfy multiple framework objectives (e.g., NIST CSF Identify & Protect, ISO 27001 Access Control) with a single control evidence set.
Who Is Affected – Cryptocurrency exchanges and other financial‑services platforms that manage hot‑wallet assets.
Recommended Actions
- Conduct an immediate privileged‑access review of all backend services and enforce least‑privilege principles.
- Deploy multi‑factor authentication and session‑recording for any accounts that can initiate wallet transfers.
- Implement continuous transaction monitoring with tamper‑evident logging to create a defensible audit trail.
- Segment hot‑wallet infrastructure from broader services and apply strict network‑level controls.
- Collect and retain evidence of these controls for audit readiness and potential regulatory inquiries.
Source: The Hacker News
Technical Notes – The breach stemmed from a backend compromise (likely a vulnerability exploit) that gave attackers the ability to initiate transfers from hot/warm wallets. No cold‑wallet assets were reported stolen.