Home › Intelligence › Brief
BREACH BRIEF 🟠 High Breach

Crypto Exchange Bitget Loses $387 Million in Unauthorized Wallet Transfers Linked to North Korean Hackers

Bitget confirmed that hackers breached its wallet‑service backend, stealing $387.5 million in crypto assets. The breach highlights gaps in privileged‑access controls and the need for continuous monitoring to satisfy audit and trust requirements.

Verisq™ Intelligence · 📅 September 25, 2026 · 📰 therecord.media
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
therecord.media

Crypto Exchange Bitget Loses $387 Million in Unauthorized Wallet Transfers Linked to North Korean Hackers

What Happened – Hackers breached Bitget’s backend wallet‑service system and exploited vulnerabilities to initiate unauthorized transfers of ETH, XRP, USDC and other tokens, resulting in an estimated loss of $387.5 million.

Why It Matters for Trust & Control Assurance

  • The incident exemplifies a failure to enforce strict access controls and privileged‑account monitoring over high‑value crypto‑wallet infrastructure.
  • Continuous control‑assurance programs that log privileged actions, enforce least‑privilege policies, and provide real‑time anomaly detection could have surfaced the illicit transfers earlier.
  • Verisq’s Access Controls capability supplies the evidence‑ready audit trail needed to demonstrate that wallet‑service permissions are continuously verified and any deviation is promptly escalated.

Who Is Affected – Crypto‑exchange platforms, digital‑asset custodians, and broader financial‑services firms that manage on‑chain assets.

Recommended Actions

  • Conduct an immediate privileged‑access review of all wallet‑service accounts and enforce least‑privilege principles.
  • Deploy continuous monitoring of transaction patterns and enforce real‑time alerts for anomalous transfers.
  • Update incident‑response playbooks to include forensic capture of on‑chain signatures and coordination with law‑enforcement. Source: https://therecord.media/crypto-ceo-accuses-north-korea-of-387-million-theft

Technical Notes – Attackers leveraged unknown backend vulnerabilities to gain write access to wallet APIs, enabling bulk token transfers. No specific CVE was disclosed. The breach was detected by Bitget’s internal monitoring, followed by emergency protocols and a temporary suspension of withdrawals. Source: https://therecord.media/crypto-ceo-accuses-north-korea-of-387-million-theft

📰 Original Source
https://therecord.media/crypto-ceo-accuses-north-korea-of-387-million-theft ↗

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →