Home › Intelligence › Brief
BREACH BRIEF 🟠 High Breach

Hackers Steal $351.6 Million from Bitget Crypto Exchange via Backend Wallet Compromise

Bitget disclosed that suspected North‑Korean actors compromised its wallet‑service backend, forging transaction data and moving $351.6 million across multiple blockchains. The breach highlights the need for robust access‑control and transaction‑authorization controls to satisfy audit and regulator scrutiny.

Verisq™ Intelligence · 📅 September 25, 2026 · 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
2 recommended
📰
Source
bleepingcomputer.com

Hackers Steal $351.6 Million from Bitget Crypto Exchange via Backend Wallet Compromise

What Happened – North‑Korean‑linked hackers breached Bitget’s backend wallet‑service system, spoofed transaction data and triggered the platform’s signing process to move assets. The attack resulted in the unauthorized transfer of roughly $351.6 million across multiple blockchain networks.

Why It Matters for Trust & Control Assurance

  • The incident illustrates a failure of access‑control and transaction‑authorization safeguards that continuous‑control programs are built to detect and evidence.
  • Real‑time monitoring of privileged actions and immutable audit trails are essential to prove due‑diligence during investigations and regulator reviews.
  • Demonstrable segregation of duties around signing keys is a core control objective that maps to many frameworks (e.g., NIST CSF 2.0, ISO 27001).

Who Is Affected – Crypto‑exchange operators, custodial wallet providers, and their institutional and retail customers.

Recommended Actions

  • Review and harden privileged access to wallet‑signing infrastructure (MFA, least‑privilege, separation of duties).
  • Deploy continuous transaction‑anomaly monitoring and immutable logging for all signing events.
  • Collect and retain evidence of access‑control changes to satisfy audit‑readiness requirements. Source: https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/

Technical Notes – Attackers compromised a critical backend system, forged transaction payloads and triggered the authorization‑signing workflow. The exact intrusion method (exploit, credential theft, insider) remains under investigation. Affected chains include Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. Source: https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/

📰 Original Source
https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/ ↗

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →