Just in:
Green SM starts Amsterdam electric taxi pilot // Amari Koh Samui and OZO Chaweng Samui invite active travellers to fill their trip with more of the experiences they love // Iran proposes uranium transfer in US diplomacy push // After the FOMC: my macro convictions for 2027 // UNGA 81: India Positions Itself As A Bridge Across A Fragmenting World // Google, OpenAI and Anthropic advance AI standards plan // Binzhou Aerospace Exploration Center, New Landmark for Science, Cultural Tourism // From Holiday Getaways to Meaningful Journeys: How Le Méridien Phuket Mai Khao Beach Resort Is Reshaping the Festive Season // President Xi Dominates US-China Summit, But Trump Has His Winning Cards // Kweichow Zhenjiu Partners with CDF Cruise to Host Exclusive Tasting Event Aboard “Adora Magic City” // NVIDIA opens viral protein map with BioNeMo pipeline // RemControl enables remote takeover of Android banking devices // Keralam Govt Stays Implementation Of Minimum Marks In Schools // Angel Health Wan Chai Clinic Commences Operations, Providing General Practice, Health Check and Vaccination Services // Long-lived Linux kernel flaw permits root container escape // From City Apartments to Villa Communities: Exploring Binghatti’s Dubai Portfolio // Huagui Group: A Global Player Across Two RMB100-Billion Aquatic Markets, as Honghu Lotus Root Ranks No. 1 in Antioxidant Content // Discord deploys machine learning to classify user ages // Bitcoin rally lifts Tesla holdings towards $1 billion // MIHAS Awards 2026 Celebrates Excellence and Sets New Benchmark for Innovation, Sustainability and Digitalisation Across the Global Halal Ecosystem //

Bitget chief links $387.5 million breach to North Korea

Bitget chief executive Gracy Chen has said preliminary evidence indicates North Korean-linked hackers were likely behind a security breach that transferred about $387.5 million in crypto assets from the exchange’s wallets.

The assessment remains unconfirmed, but Chen said investigators had identified internet protocol behaviour and on-chain patterns consistent with techniques used by known North Korean hacking organisations. Bitget has not publicly named a specific group, and the investigation is continuing with cybersecurity firms Mandiant and SlowMist and relevant authorities.

Bitget on Friday raised its estimate of assets transferred to attacker-controlled addresses from $351.6 million to approximately $387.5 million. The company said the increase reflected a fuller accounting of the same September 24 incident, including Zcash and TRON assets omitted from its initial calculation, rather than additional unauthorised transfers.

The exchange said its security systems detected unauthorised transfers at 18:31 UTC on September 24 involving a limited number of hot and warm wallets. Its cold wallets were not affected, while the separate self-custodial Bitget Wallet operates on independent infrastructure and was also unaffected.

Chen said the attacker compromised a critical backend system within Bitget’s wallet infrastructure, spoofing transaction data and invoking authorisation processes to transfer assets. She said private keys were not compromised. Bitget later said it had identified the attack path and the method used to bypass existing security controls, and had remediated the underlying vulnerability.

The affected assets included XRP, Ether, Tether, Zcash, USD Coin, USDT0, Tether Gold, BNB, Avalanche and TRX, spread across Ethereum and other Ethereum Virtual Machine networks, the XRP Ledger, Zcash and TRON. Bitget said the incident had been contained and no further unauthorised transfers were possible.

The exchange temporarily suspended withdrawals while deposits and trading continued. It has now set out a phased restoration schedule, with Bitcoin withdrawals due to resume on September 28, followed by Ether on September 29 and USDT on September 30. Withdrawals for other tokens, along with fiat and peer-to-peer services, are scheduled to return on October 2.

Bitget has maintained that customer account balances remain accurate and that users will not bear losses arising from the breach. Chen said the financial impact falls within the coverage of the company’s User Protection Fund, which Bitget valued at more than $464 million after the attack.

Bitget said the protection fund held 5,500 Bitcoin, worth about $464 million at the time of its statement, and was designed to provide a safeguard for users during security events. The company said the breach did not require customers to absorb the transferred assets. The fund’s value can fluctuate with Bitcoin prices, making the size of the buffer variable even when its cryptocurrency holdings remain unchanged.

The company has also launched a recovery bounty programme aimed at encouraging assistance in freezing or recovering stolen assets. Under the scheme, eligible parties whose voluntary actions directly result in funds being frozen can receive a bounty equal to 5 per cent of the amount successfully frozen, with further rewards available for recovered assets.

Some stolen funds have already been frozen through coordination with industry participants, according to Bitget. Blockchain investigators have separately tracked rapid movements and conversions of parts of the stolen portfolio across several networks, complicating recovery efforts while leaving substantial sums visible in attacker-controlled addresses.

The North Korea attribution is significant because blockchain intelligence firms have documented sustained theft by hacking groups linked to Pyongyang. Elliptic said the Bitget incident, if the attribution is confirmed, would push the value of crypto assets it has tracked as stolen by North Korean-linked actors during 2026 above $1 billion.

TRM Labs has also estimated that North Korea-linked groups accounted for roughly three-quarters of cryptocurrency thefts during 2026 before the Bitget investigation is completed. Such assessments are based on technical indicators, transaction tracing and behavioural similarities, but attribution in cyber incidents can change as investigations develop.

Arabian Post – Crypto News Network



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…