Key Points
Bitget hack: $351.6 million stolen from hot wallets on September 24, 2026. Lazarus Group suspected. User Protection Fund covers the loss.
▶ Bitget confirmed the Bitget hack on September 25, 2026: attackers drained $351.6 million from hot wallets detected at 18:31 UTC on September 24.
▶ Assets stolen: approximately 103 million XRP and 31,890 ETH. Cold wallets unaffected. Trading and deposits remained open throughout.
▶ Bitget CEO Gracy Chen suspects the Lazarus Group, North Korea’s state-backed hacking unit. No technical evidence has been published yet. On-chain investigator Specter linked stolen XRP to July 2026 AFX attack funds also attributed to Lazarus.
▶ The User Protection Fund held $464 million at the time of the hack, covering the full $351.6 million loss. Bitget says all customer balances are accurate and protected.
▶ An inside job has not been ruled out but CEO describes the probability as very low. No employee has been linked to the breach.
▶ This follows Lazarus Group’s $1.5 billion Bybit hack in February 2025 and the $292 million KelpDAO exploit in April 2026. North Korea has now stolen an estimated $6.75 billion in crypto cumulatively.
The Bitget hack is the largest crypto exchange theft of September 2026. At 18:31 UTC on September 24, Bitget’s security systems detected unauthorized transfers from several hot wallets. By the time Bitget CEO Gracy Chen confirmed the incident in a live broadcast on X the following morning, $351.6 million had left the exchange and approximately 103 million XRP and 31,890 ETH routed to external addresses.
Chen said Bitget believes North Korea’s Lazarus Group is responsible. No technical evidence supporting the attribution has been published as of this writing. However, on-chain investigator Specter reported that the stolen XRP, after cross-chain transfer, links directly to funds stolen in the AFX exchange attack in July 2026, which was itself attributed to TraderTraitor, a Lazarus Group subunit. The on-chain link is the most substantive piece of evidence currently available.
The single fact that will matter most to Bitget’s 20 million users: the exchange’s User Protection Fund held $464 million when the hack occurred, enough to cover the entire $351.6 million loss with $112.4 million to spare. Bitget says customer balances are accurate and protected. Withdrawals were suspended pending security review. The attack method and how the hot wallets were accessed without extracting private keys has not been explained. A full incident report was promised within 24 hours.
What Is the Bitget Hack? What We Know Right Now
In practice, this is what Bitget has confirmed and what remains unknown. Confirmed: unauthorized transfers from hot wallets detected at 18:31 UTC September 24. Assets drained: 103 million XRP and 31,890 ETH. Cold wallets not affected. Customer private keys not compromised. Trading and deposits remained available. User Protection Fund covers the loss. Withdrawals suspended.
Not confirmed: how attackers accessed the wallet management infrastructure. Whether private keys were extracted or internal systems were abused to authorize transfers. The specific wallets targeted and how many were compromised. Whether an employee assisted the attackers. When withdrawals will resume.
Chen’s description of the attack is important: she said attackers transferred funds directly rather than forging withdrawal requests from customer accounts, and that no user private keys were obtained. This suggests the attackers had access to Bitget’s internal wallet management systems or signing infrastructure, not to customer keys directly. That is the most dangerous category of exchange compromise: one that bypasses user-level security entirely by operating at the infrastructure level.
Is the Lazarus Group Behind the Bitget Hack? What the Evidence Shows
What is the Lazarus Group?
The Lazarus Group is a North Korean state-sponsored hacking operation controlled by North Korea’s Reconnaissance General Bureau. It is the primary instrument through which North Korea funds its economy under international sanctions, generating revenue through large-scale cryptocurrency theft. The FBI formally attributed the $1.5 billion Bybit hack of February 2025 to Lazarus Group’s TraderTraitor subunit. Chainalysis estimates DPRK-linked actors stole $2.02 billion in crypto during 2025, bringing their cumulative total to approximately $6.75 billion.
The attribution to Lazarus Group currently rests on two things. First, CEO Gracy Chen’s statement that she suspects Lazarus, based on the nature of the attack and her own prior experience of having approximately $80,000 stolen from a personal wallet by what she believes was the same group. Second, the on-chain analysis by Specter, who traced the stolen XRP through cross-chain transfers to addresses linked to the AFX exchange hack in July 2026, itself attributed to TraderTraitor.
The critical honest caveat: no technical evidence has been published yet. CEO statements and on-chain fund-flow similarities are indicators, not proof. Lazarus Group attribution for the Bybit hack took ZachXBT’s multi-day on-chain analysis before the FBI formally confirmed it five days later. The Bitget attribution is currently at the early stage. The full incident report promised within 24 hours may contain technical indicators that confirm or complicate the Lazarus thesis.
How Does the Bitget Hack Compare to Previous Lazarus Group Attacks?
Lazarus Group Major Crypto Exchange and Protocol Attacks: 2024 to 2026
Sources: FBI, Chainalysis, Sygnia, LayerZero, ChainCatcher, Hackread | @cryptonewsbytes
| Target | Date | Amount | Method | Attribution |
|---|---|---|---|---|
| WazirX | July 2024 | $234M | Multi-sig wallet manipulation | Confirmed Lazarus |
| Bybit | February 2025 | $1.5B | Safe wallet UI compromise, social engineering | FBI confirmed Lazarus/TraderTraitor |
| AFX Exchange | July 2026 | $24M | Unknown and linked to TraderTraitor | TraderTraitor (Lazarus subunit) |
| KelpDAO | April 2026 | $292M | Bridge exploit | Suspected Lazarus/TraderTraitor |
| Bitget | September 24, 2026 | $351.6M | Internal wallet infrastructure breach | Suspected Lazarus (unconfirmed) |
Cumulative estimated DPRK crypto theft: $6.75 billion (Chainalysis, 2026). | Sources: FBI advisory Feb 2025, Chainalysis 2026, LayerZero April 2026, ChainCatcher Sep 25 2026 | @cryptonewsbytes
What Is the Bitget User Protection Fund and Will It Actually Cover Users?
Bitget launched its User Protection Fund in 2022 following a series of high-profile exchange collapses including FTX, Celsius, and Voyager. The fund holds assets in reserve specifically to compensate users in the event of a security incident. As of September 24, 2026, the fund held more than $464 million. The stolen amount was $351.6 million. The fund exceeds the loss by approximately $112.4 million.
Whether the fund actually covers users depends on several things Bitget has not yet clarified: how the fund’s value is calculated (whether it is held in stable assets or includes crypto that fluctuates), how and when claims will be processed, and whether any customers will need to submit individual claims or whether the reimbursement will be automatic. Bitget said customer balances are “accurate and protected” but has not described the reimbursement mechanism.
How does this compare to FTX, Celsius, and Voyager?
FTX collapsed in November 2022 with an $8.7 billion hole in customer assets. Customer payouts from the FTX bankruptcy estate began only in 2024. Celsius classified customer earn deposits as estate property and paid back cents on the dollar after two years of bankruptcy proceedings. Voyager distributed approximately 35 cents per dollar initially. Bitget’s User Protection Fund, if it functions as described, represents a fundamentally different outcome: full reimbursement without bankruptcy proceedings, immediately. The key difference from those exchanges is that Bitget’s hack did not create a solvency problem. The exchange has more assets than were stolen. The fund is a pre-funded insurance mechanism, not a claim against a bankrupt estate.
What Does the Bitget Hack Mean for Crypto Exchange Security in 2026?
The Bitget hack follows a pattern that security researchers have warned about throughout 2026: attacks targeting internal exchange infrastructure rather than exploiting blockchain-level vulnerabilities. The Bybit hack in February 2025 compromised the user interface of Safe’s wallet management software to make malicious transactions appear legitimate to signers. The Bitget attack, if Chen’s description is accurate, compromised internal wallet management systems to authorize transfers without extracting user keys.
Both attacks share the same fundamental characteristic: they bypassed the cryptographic security of the blockchain entirely by attacking the operational layer that sits between the exchange’s infrastructure and the blockchain. No amount of proof-of-work or proof-of-stake security prevents an attacker who has access to the internal systems authorizing transactions from moving funds. The Hacken Q2 2026 Security Report CNB covered found that 88% of crypto losses came from operational failures rather than code exploits. The Bitget hack is another data point in that pattern.
The specific implication for exchange users: the security of your funds at a centralised exchange is not primarily a question of whether the blockchain is secure. It is a question of whether the exchange’s internal systems, access controls, employee screening, and operational security are strong enough to prevent an attacker with nation-state resources and months of preparation from finding a path in. Lazarus Group, if confirmed as the attacker, has defeated those defences at WazirX, Bybit, and now apparently Bitget in an 18-month window.
What Should Bitget Users Do Right Now?
Your funds are stated as covered and but verify your balance
Bitget says all customer balances are accurate and protected by the User Protection Fund. Log in and confirm your balance matches your expectations. If there is any discrepancy, contact Bitget support immediately and document it with screenshots.
Withdrawals are suspended and plan accordingly
Bitget suspended withdrawals during the security review. Do not rely on Bitget funds for time-sensitive obligations until withdrawals resume. Monitor Bitget’s official X account and blog for the restoration timeline.
Watch for phishing attempts using this news
Major exchange hacks generate immediate phishing campaigns impersonating the exchange. Emails, Telegram messages, or social media posts claiming to offer refund forms, withdrawal restoration links, or special customer support numbers should be treated as scams. Go only to bitget.com directly.
Read the 24-hour incident report when it publishes
Bitget promised a full technical incident report within 24 hours of the September 24 detection. That report will contain the attack method, which wallets were affected, and the evidence connecting the attack to Lazarus Group. The report will also clarify the reimbursement process.
Reconsider hot wallet exposure on any exchange
The Bitget hack is a reminder that assets held in exchange hot wallets carry a risk profile that cold wallets and self-custody do not. If you hold material crypto on any centralised exchange, assess what portion of that exposure is necessary for active trading versus what could be moved to self-custody.
Frequently Asked Questions
What happened in the Bitget hack?
Bitget confirmed on September 25, 2026 that attackers stole approximately $351.6 million and including 103 million XRP and 31,890 ETH and from hot wallets after gaining unauthorized access to part of its wallet infrastructure. The incident was detected at 18:31 UTC on September 24. Cold wallets were not affected. Customer private keys were not compromised. The attack exploited Bitget’s internal wallet management infrastructure rather than customer accounts directly.
Was the Bitget hack carried out by North Korea’s Lazarus Group?
Bitget CEO Gracy Chen suspects North Korea’s Lazarus Group based on the nature of the attack and a prior personal experience. On-chain investigator Specter linked the stolen XRP through cross-chain transfers to funds from the July 2026 AFX exchange hack, itself attributed to TraderTraitor, a Lazarus Group subunit. No technical evidence has been publicly published. Bitget promised a full incident report within 24 hours that may contain definitive attribution indicators.
Will Bitget users get their money back?
Bitget says all customer balances are accurate and protected by its User Protection Fund, which held $464 million at the time of the hack and exceeding the $351.6 million stolen amount by approximately $112.4 million. The exchange has not detailed the reimbursement mechanism or timeline. Based on Bitget’s statements, no customer should experience a loss, but the specific process has not been published.
How does the Bitget hack compare to the Bybit hack?
The Bybit hack in February 2025 was $1.5 billion, confirmed by the FBI as the work of North Korea’s Lazarus Group TraderTraitor subunit. Bybit used its own reserves and emergency funding to cover user losses without a dedicated protection fund. The Bitget hack at $351.6 million is approximately one-quarter the size of Bybit. Bitget has a dedicated User Protection Fund that covers the full amount. Both attacks appear to have targeted internal exchange infrastructure rather than blockchain-level vulnerabilities.
Is it safe to use Bitget after the hack?
Bitget has suspended withdrawals pending a security review and says it will restore them after confirming system security. Customer balances are stated as protected. The key unknowns are: how the hack occurred and whether the vulnerability has been identified and closed. The 24-hour incident report will be the most important document for assessing whether the exchange’s systems are secure. Until that report is published and reviewed, exercising caution about the level of funds held on the exchange is reasonable.
What is Lazarus Group’s total crypto theft?
Chainalysis estimates that DPRK-linked actors stole $2.02 billion in crypto during 2025 alone, lifting their cumulative total to approximately $6.75 billion. Major confirmed and suspected Lazarus attacks include: WazirX ($234M, 2024), Bybit ($1.5B, 2025), KelpDAO ($292M, April 2026), AFX Exchange ($24M, July 2026), and now Bitget ($351.6M, September 2026).
Further Reading
The Hacken Q2 2026 report on why operational failures, not smart contract bugs, drive the majority of crypto losses. The Bitget hack fits squarely in the 88%.
The September 15 rsETH exploit where a MEV bot out-raced the attacker. The contrast with Bitget is instructive: on-chain exploits can be front-run, internal infrastructure breaches cannot.
Another operational security failure in 2026: a private key leaked through GitHub configuration. Different attack vector, same lesson. Infrastructure security is the primary attack surface.
Sources: Hackread September 25 2026 (primary: Bitget CEO Gracy Chen live broadcast, $351.6M confirmed), ChainCatcher September 25 2026 (primary: Specter on-chain analysis, XRP/ETH amounts, AFX connection), Chainalysis 2026 DPRK cumulative theft estimates ($6.75B), Sygnia Bybit investigation June 2026 (Lazarus Group TraderTraitor methodology), FBI advisory February 2025 (Bybit/TraderTraitor formal attribution), LayerZero KelpDAO post-mortem April 2026 | Published September 25, 2026 | CryptoNewsBytes.com | Not financial advice.
Key Points
Bitget hack: $351.6 million stolen from hot wallets on September 24, 2026. Lazarus Group suspected. User Protection Fund covers the loss.
▶ Bitget confirmed the Bitget hack on September 25, 2026: attackers drained $351.6 million from hot wallets detected at 18:31 UTC on September 24.
▶ Assets stolen: approximately 103 million XRP and 31,890 ETH. Cold wallets unaffected. Trading and deposits remained open throughout.
▶ Bitget CEO Gracy Chen suspects the Lazarus Group, North Korea’s state-backed hacking unit. No technical evidence has been published yet. On-chain investigator Specter linked stolen XRP to July 2026 AFX attack funds also attributed to Lazarus.
▶ The User Protection Fund held $464 million at the time of the hack, covering the full $351.6 million loss. Bitget says all customer balances are accurate and protected.
▶ An inside job has not been ruled out but CEO describes the probability as very low. No employee has been linked to the breach.
▶ This follows Lazarus Group’s $1.5 billion Bybit hack in February 2025 and the $292 million KelpDAO exploit in April 2026. North Korea has now stolen an estimated $6.75 billion in crypto cumulatively.
The Bitget hack is the largest crypto exchange theft of September 2026. At 18:31 UTC on September 24, Bitget’s security systems detected unauthorized transfers from several hot wallets. By the time Bitget CEO Gracy Chen confirmed the incident in a live broadcast on X the following morning, $351.6 million had left the exchange and approximately 103 million XRP and 31,890 ETH routed to external addresses.
Chen said Bitget believes North Korea’s Lazarus Group is responsible. No technical evidence supporting the attribution has been published as of this writing. However, on-chain investigator Specter reported that the stolen XRP, after cross-chain transfer, links directly to funds stolen in the AFX exchange attack in July 2026, which was itself attributed to TraderTraitor, a Lazarus Group subunit. The on-chain link is the most substantive piece of evidence currently available.
The single fact that will matter most to Bitget’s 20 million users: the exchange’s User Protection Fund held $464 million when the hack occurred, enough to cover the entire $351.6 million loss with $112.4 million to spare. Bitget says customer balances are accurate and protected. Withdrawals were suspended pending security review. The attack method and how the hot wallets were accessed without extracting private keys has not been explained. A full incident report was promised within 24 hours.
What Is the Bitget Hack? What We Know Right Now
In practice, this is what Bitget has confirmed and what remains unknown. Confirmed: unauthorized transfers from hot wallets detected at 18:31 UTC September 24. Assets drained: 103 million XRP and 31,890 ETH. Cold wallets not affected. Customer private keys not compromised. Trading and deposits remained available. User Protection Fund covers the loss. Withdrawals suspended.
Not confirmed: how attackers accessed the wallet management infrastructure. Whether private keys were extracted or internal systems were abused to authorize transfers. The specific wallets targeted and how many were compromised. Whether an employee assisted the attackers. When withdrawals will resume.
Chen’s description of the attack is important: she said attackers transferred funds directly rather than forging withdrawal requests from customer accounts, and that no user private keys were obtained. This suggests the attackers had access to Bitget’s internal wallet management systems or signing infrastructure, not to customer keys directly. That is the most dangerous category of exchange compromise: one that bypasses user-level security entirely by operating at the infrastructure level.
Is the Lazarus Group Behind the Bitget Hack? What the Evidence Shows
What is the Lazarus Group?
The Lazarus Group is a North Korean state-sponsored hacking operation controlled by North Korea’s Reconnaissance General Bureau. It is the primary instrument through which North Korea funds its economy under international sanctions, generating revenue through large-scale cryptocurrency theft. The FBI formally attributed the $1.5 billion Bybit hack of February 2025 to Lazarus Group’s TraderTraitor subunit. Chainalysis estimates DPRK-linked actors stole $2.02 billion in crypto during 2025, bringing their cumulative total to approximately $6.75 billion.
The attribution to Lazarus Group currently rests on two things. First, CEO Gracy Chen’s statement that she suspects Lazarus, based on the nature of the attack and her own prior experience of having approximately $80,000 stolen from a personal wallet by what she believes was the same group. Second, the on-chain analysis by Specter, who traced the stolen XRP through cross-chain transfers to addresses linked to the AFX exchange hack in July 2026, itself attributed to TraderTraitor.
The critical honest caveat: no technical evidence has been published yet. CEO statements and on-chain fund-flow similarities are indicators, not proof. Lazarus Group attribution for the Bybit hack took ZachXBT’s multi-day on-chain analysis before the FBI formally confirmed it five days later. The Bitget attribution is currently at the early stage. The full incident report promised within 24 hours may contain technical indicators that confirm or complicate the Lazarus thesis.
How Does the Bitget Hack Compare to Previous Lazarus Group Attacks?
Lazarus Group Major Crypto Exchange and Protocol Attacks: 2024 to 2026
Sources: FBI, Chainalysis, Sygnia, LayerZero, ChainCatcher, Hackread | @cryptonewsbytes
| Target | Date | Amount | Method | Attribution |
|---|---|---|---|---|
| WazirX | July 2024 | $234M | Multi-sig wallet manipulation | Confirmed Lazarus |
| Bybit | February 2025 | $1.5B | Safe wallet UI compromise, social engineering | FBI confirmed Lazarus/TraderTraitor |
| AFX Exchange | July 2026 | $24M | Unknown and linked to TraderTraitor | TraderTraitor (Lazarus subunit) |
| KelpDAO | April 2026 | $292M | Bridge exploit | Suspected Lazarus/TraderTraitor |
| Bitget | September 24, 2026 | $351.6M | Internal wallet infrastructure breach | Suspected Lazarus (unconfirmed) |
Cumulative estimated DPRK crypto theft: $6.75 billion (Chainalysis, 2026). | Sources: FBI advisory Feb 2025, Chainalysis 2026, LayerZero April 2026, ChainCatcher Sep 25 2026 | @cryptonewsbytes
What Is the Bitget User Protection Fund and Will It Actually Cover Users?
Bitget launched its User Protection Fund in 2022 following a series of high-profile exchange collapses including FTX, Celsius, and Voyager. The fund holds assets in reserve specifically to compensate users in the event of a security incident. As of September 24, 2026, the fund held more than $464 million. The stolen amount was $351.6 million. The fund exceeds the loss by approximately $112.4 million.
Whether the fund actually covers users depends on several things Bitget has not yet clarified: how the fund’s value is calculated (whether it is held in stable assets or includes crypto that fluctuates), how and when claims will be processed, and whether any customers will need to submit individual claims or whether the reimbursement will be automatic. Bitget said customer balances are “accurate and protected” but has not described the reimbursement mechanism.
How does this compare to FTX, Celsius, and Voyager?
FTX collapsed in November 2022 with an $8.7 billion hole in customer assets. Customer payouts from the FTX bankruptcy estate began only in 2024. Celsius classified customer earn deposits as estate property and paid back cents on the dollar after two years of bankruptcy proceedings. Voyager distributed approximately 35 cents per dollar initially. Bitget’s User Protection Fund, if it functions as described, represents a fundamentally different outcome: full reimbursement without bankruptcy proceedings, immediately. The key difference from those exchanges is that Bitget’s hack did not create a solvency problem. The exchange has more assets than were stolen. The fund is a pre-funded insurance mechanism, not a claim against a bankrupt estate.
What Does the Bitget Hack Mean for Crypto Exchange Security in 2026?
The Bitget hack follows a pattern that security researchers have warned about throughout 2026: attacks targeting internal exchange infrastructure rather than exploiting blockchain-level vulnerabilities. The Bybit hack in February 2025 compromised the user interface of Safe’s wallet management software to make malicious transactions appear legitimate to signers. The Bitget attack, if Chen’s description is accurate, compromised internal wallet management systems to authorize transfers without extracting user keys.
Both attacks share the same fundamental characteristic: they bypassed the cryptographic security of the blockchain entirely by attacking the operational layer that sits between the exchange’s infrastructure and the blockchain. No amount of proof-of-work or proof-of-stake security prevents an attacker who has access to the internal systems authorizing transactions from moving funds. The Hacken Q2 2026 Security Report CNB covered found that 88% of crypto losses came from operational failures rather than code exploits. The Bitget hack is another data point in that pattern.
The specific implication for exchange users: the security of your funds at a centralised exchange is not primarily a question of whether the blockchain is secure. It is a question of whether the exchange’s internal systems, access controls, employee screening, and operational security are strong enough to prevent an attacker with nation-state resources and months of preparation from finding a path in. Lazarus Group, if confirmed as the attacker, has defeated those defences at WazirX, Bybit, and now apparently Bitget in an 18-month window.
What Should Bitget Users Do Right Now?
Your funds are stated as covered and but verify your balance
Bitget says all customer balances are accurate and protected by the User Protection Fund. Log in and confirm your balance matches your expectations. If there is any discrepancy, contact Bitget support immediately and document it with screenshots.
Withdrawals are suspended and plan accordingly
Bitget suspended withdrawals during the security review. Do not rely on Bitget funds for time-sensitive obligations until withdrawals resume. Monitor Bitget’s official X account and blog for the restoration timeline.
Watch for phishing attempts using this news
Major exchange hacks generate immediate phishing campaigns impersonating the exchange. Emails, Telegram messages, or social media posts claiming to offer refund forms, withdrawal restoration links, or special customer support numbers should be treated as scams. Go only to bitget.com directly.
Read the 24-hour incident report when it publishes
Bitget promised a full technical incident report within 24 hours of the September 24 detection. That report will contain the attack method, which wallets were affected, and the evidence connecting the attack to Lazarus Group. The report will also clarify the reimbursement process.
Reconsider hot wallet exposure on any exchange
The Bitget hack is a reminder that assets held in exchange hot wallets carry a risk profile that cold wallets and self-custody do not. If you hold material crypto on any centralised exchange, assess what portion of that exposure is necessary for active trading versus what could be moved to self-custody.
Frequently Asked Questions
What happened in the Bitget hack?
Bitget confirmed on September 25, 2026 that attackers stole approximately $351.6 million and including 103 million XRP and 31,890 ETH and from hot wallets after gaining unauthorized access to part of its wallet infrastructure. The incident was detected at 18:31 UTC on September 24. Cold wallets were not affected. Customer private keys were not compromised. The attack exploited Bitget’s internal wallet management infrastructure rather than customer accounts directly.
Was the Bitget hack carried out by North Korea’s Lazarus Group?
Bitget CEO Gracy Chen suspects North Korea’s Lazarus Group based on the nature of the attack and a prior personal experience. On-chain investigator Specter linked the stolen XRP through cross-chain transfers to funds from the July 2026 AFX exchange hack, itself attributed to TraderTraitor, a Lazarus Group subunit. No technical evidence has been publicly published. Bitget promised a full incident report within 24 hours that may contain definitive attribution indicators.
Will Bitget users get their money back?
Bitget says all customer balances are accurate and protected by its User Protection Fund, which held $464 million at the time of the hack and exceeding the $351.6 million stolen amount by approximately $112.4 million. The exchange has not detailed the reimbursement mechanism or timeline. Based on Bitget’s statements, no customer should experience a loss, but the specific process has not been published.
How does the Bitget hack compare to the Bybit hack?
The Bybit hack in February 2025 was $1.5 billion, confirmed by the FBI as the work of North Korea’s Lazarus Group TraderTraitor subunit. Bybit used its own reserves and emergency funding to cover user losses without a dedicated protection fund. The Bitget hack at $351.6 million is approximately one-quarter the size of Bybit. Bitget has a dedicated User Protection Fund that covers the full amount. Both attacks appear to have targeted internal exchange infrastructure rather than blockchain-level vulnerabilities.
Is it safe to use Bitget after the hack?
Bitget has suspended withdrawals pending a security review and says it will restore them after confirming system security. Customer balances are stated as protected. The key unknowns are: how the hack occurred and whether the vulnerability has been identified and closed. The 24-hour incident report will be the most important document for assessing whether the exchange’s systems are secure. Until that report is published and reviewed, exercising caution about the level of funds held on the exchange is reasonable.
What is Lazarus Group’s total crypto theft?
Chainalysis estimates that DPRK-linked actors stole $2.02 billion in crypto during 2025 alone, lifting their cumulative total to approximately $6.75 billion. Major confirmed and suspected Lazarus attacks include: WazirX ($234M, 2024), Bybit ($1.5B, 2025), KelpDAO ($292M, April 2026), AFX Exchange ($24M, July 2026), and now Bitget ($351.6M, September 2026).
Further Reading
The Hacken Q2 2026 report on why operational failures, not smart contract bugs, drive the majority of crypto losses. The Bitget hack fits squarely in the 88%.
The September 15 rsETH exploit where a MEV bot out-raced the attacker. The contrast with Bitget is instructive: on-chain exploits can be front-run, internal infrastructure breaches cannot.
Another operational security failure in 2026: a private key leaked through GitHub configuration. Different attack vector, same lesson. Infrastructure security is the primary attack surface.
Sources: Hackread September 25 2026 (primary: Bitget CEO Gracy Chen live broadcast, $351.6M confirmed), ChainCatcher September 25 2026 (primary: Specter on-chain analysis, XRP/ETH amounts, AFX connection), Chainalysis 2026 DPRK cumulative theft estimates ($6.75B), Sygnia Bybit investigation June 2026 (Lazarus Group TraderTraitor methodology), FBI advisory February 2025 (Bybit/TraderTraitor formal attribution), LayerZero KelpDAO post-mortem April 2026 | Published September 25, 2026 | CryptoNewsBytes.com | Not financial advice.

