CTIPilot

Bitget hot/warm-wallet theft (September 2026)

incident · incident:bitget-hot-wallet-theft-2026-09

2026-09-24 theft of approximately $388M from cryptocurrency exchange Bitget's hot and warm wallet infrastructure via a compromised third-party security product used to obtain internal credentials and spoof withdrawal-authorization data; suspected North Korea-linked (TraderTraitor/Jade Sleet) per Bitget's CEO and TRM Labs' on-chain laundering-infrastructure overlap analysis, not definitively attributed (Bitget, TRM Labs, 2026-09-25/27). TRM Labs: on-chain laundering infrastructure overlaps wallets used in the 2025 Bybit and AFX Bridge hacks, both attributed to the TraderTraitor cluster; TRM states attribution is not definitive, so no formal relation edge is recorded pending confirmation.

Coverage timeline
1
first 2026-09-29 → last 2026-09-29
Peak priority
high
1 high
Sources cited
4
3 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Co-occurring entities below
ATT&CK techniques
3
pinned v19.2 · see below

ATT&CK techniques

3 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-29/bitget-hot-wallet-theft-north-korea-nexus · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-29/bitget-hot-wallet-theft-north-korea-nexus · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-29/bitget-hot-wallet-theft-north-korea-nexus · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-29/bitget-hot-wallet-theft-north-korea-nexus · ATT&CK page ↗

Impact TA0040

T1565.002Data Manipulation: Transmitted Data Manipulation×1

Adversaries may alter data en route to storage or other systems in order to manipulate external outcomes or hide activity, thus threatening the integrity of the data. By manipulating transmitted data, adversaries may attempt to affect a business process, organizational understanding, and decision making.

Evidence: 2026-09-29/bitget-hot-wallet-theft-north-korea-nexus · ATT&CK page ↗

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-09-29/bitget-hot-wallet-theft-north-korea-nexus · ATT&CK page ↗

Story timeline

  1. 2026-09-29Bitget: an attacker exploited a third-party security product to obtain internal credentials, spoofed wallet-authorization data, and stole $388M in one of 2026's largest crypto-exchange hacks
    active-threatsA compromised third-party security tool, not a private-key theft, let an attacker forge Bitget's own withdrawal approvals

Where this entity is cited

  • active-threats1

Source distribution

  • thehackernews.com2 (50%)
  • bitget.com1 (25%)
  • trmlabs.com1 (25%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Bitget hot/warm-wallet theft (September 2026) (1)

2026-09-29 · view entry permalink →

HIGHNATOB2

Bitget: an attacker exploited a third-party security product to obtain internal credentials, spoofed wallet-authorization data, and stole $388M in one of 2026's largest crypto-exchange hacks

Cryptocurrency exchange Bitget confirms that, at 18:31 UTC on 2026-09-24, unauthorized transfers occurred from a portion of its hot and warm wallet infrastructure across eleven blockchains: Ethereum, XRP Ledger, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, Celestia and Zcash (Bitget, 2026-09-27). Per Bitget's own investigation, the attacker did not steal a private key: "the attacker may have exploited a vulnerability in a third-party security product to potentially obtain high-level internal credentials," then used those credentials "to impersonate authorized activity and send fraudulent withdrawal commands to the wallet system," bypassing existing risk controls (Bitget, 2026-09-27). CEO Gracy Chen described the mechanism directly: "The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out" (The Hacker News, 2026-09-25). Bitget states private-key compromise was ruled out and cold wallets were unaffected; the vulnerable third-party product's vendor was notified and the affected functionality disabled pending a fix.

Total loss is now estimated at approximately $388M, revised up from an initial roughly $351.6M on-chain estimate, across twelve wallet addresses. Bitget's approximately $464M User Protection Fund will cover the loss, customer account balances, deposits and trading were unaffected, and withdrawals, paused at detection, resumed in phases starting with Bitcoin on 2026-09-28. Bitget revoked and reissued internal login credentials, restructured access to highly sensitive systems, now requires multiple approvals for critical operations, and engaged Mandiant and SlowMist for independent forensics (Bitget, 2026-09-27).

Bitget's CEO called North Korean involvement "very likely," based on the team's preliminary investigation linking observed IP addresses to VPN services associated with a North Korean hacking group (TRM Labs, 2026-09-25). TRM Labs, an independent blockchain-forensics firm, reports that on-chain tracing shows the wallets laundering Bitget's stolen funds overlap with wallets previously used to launder proceeds from the 2025 Bybit and AFX Bridge hacks, both attributed to the DPRK-linked TraderTraitor cluster (also known as UNC4899/PUKCHONG): "these onchain links confirm the group laundering these proceeds is the same one used by TraderTraitor in other recent hacks" (TRM Labs, 2026-09-25). TRM is explicit that this stops short of definitive attribution: "TRM has not yet definitively attributed the exploit to North Korea" and "another actor carrying out the theft remains technically possible."

the attacker may have exploited a vulnerability in a third-party security product to potentially obtain high-level internal credentials

Bitget (official incident page) 2026-09-27

The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out.

Bitget CEO Gracy Chen, via The Hacker News

these onchain links confirm the group laundering these proceeds is the same one used by TraderTraitor in other recent hacks

TRM Labs 2026-09-25

Builds on: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop

incident29 Sep 05:15Zmulti-sourceOpen finding ↗