UNICORN⚡️🦄|9月 25, 2026 07:17
General Kim of North Korea treated the cryptocurrency exchange as an ATM, and $350 million was stolen from Bitget
Compared to before, Bybit's Safe multi signature front-end was tampered with, and the signer thought they were signing a normal transaction
Bitget was not breached by a single wallet or currency this time, but by the exploitation of the backend authorization process itself, involving dozens of assets and several chains
What is the current status
Withdrawals are still suspended, recharges and transactions are normal
Its CEO Gracy Chen said that recovery would take several hours to several days, not weeks, but refused to give a specific time. The original statement was that she did not promise a time window that could not be guaranteed
Suspend coverage of all 4930 Bitget currency networks. BGB is now 1.98, down 2.5%
timeline
On September 24th at 18:31 UTC (Beijing 25th at 2:31 am), the first abnormal transfer was made, mainly in ETH
Half an hour later, an XRP hot wallet began to make large transfers, which was the largest transaction
The attacker concentrated the transfer until 19:16 UTC
21:30 UTC, Chen made an announcement
At 21:41 UTC, there are still funds going out, which is 10 minutes later than the announcement
Bitget later identified 52 meaningful transfers, of which 19 were confirmed to have been made by attackers, corresponding to approximately $351 million
How did the money go out
The biggest single loss comes from an XRP hot wallet
Ranked by chain, XRP and Ethereum suffer the greatest losses, while also involving Arbitrarum, Optimism, Base, BNB Chain, Avalanche
XRP 102.93 million pieces (157 million)
ETH 31, 890 pieces (85.75 million)
USDT 34.75 million
USDC 21.05 million
USDT0 19.67 million
XAUt 3000 pieces (12.82 million)
BNB 9.88 million
AVAX 8.38 million
TRX 7.07 million
Ethereum and Arbitrarum alone have 133.4 million legs
Convert all stablecoins to ETH using Uniswap X and 1-inch Fusion, with a 5% premium accepted, just for the sake of speed
USDT and USDC can be frozen by the issuer, while ETH cannot
official statement
Chen wrote on X that the attacker invaded a critical backend system in the wallet infrastructure, used it to forge transaction data, triggered the authorization process, and transferred money out
Private key leakage has been ruled out, no forged user withdrawal requests have been made, and losses have been controlled
The cold wallet is fine, it only affects some hot wallets and warm wallets. Full coverage of $464 million user protection fund, in addition to $1 billion of self owned funds and 1:1 reserve of user assets
In the live broadcast, she added a sentence that preliminarily judged it to be a supply chain attack, and the one that was breached was a third-party tool used by Bitget in daily life
An independent third-party security team has been commissioned to enter the site, and withdrawals will only resume after all vulnerabilities have been identified and fixed
Additionally, there is a possibility of recovering some of the funds
The real culprit's line
On chain detective Specter traced the stolen XRP to an Ethereum address that received 68808 USDT. The wallet used for the transfer had previously been transferred ETH to an address labeled AFX EXPLOITER
AFX is a protocol on Arbitrum, which was attacked by a bridge on July 22 and took $24.15 million. Its own review named Trader Raitor, which is a subgroup under Lazarus
Earlier, LayerZero grouped the KelpDAO bridge attack in April under the same group
Chen said 'very likely to be North Korea', but did not name it
She also emphasized that this time is different from the Bybit incident in 2025
Bybit is a Safe multi signature front-end that has been tampered with, and the signer thought they were signing a normal transaction
Bitget was not breached by a single wallet or currency this time, but by the exploitation of the backend authorization process itself, involving dozens of assets and several chains
So I dare not resume withdrawals first, fearing that the same pipeline will be used a second time
Bybit's Ben Zhou publicly responded, the team is on standby at any time, and is updating http://(LazarusBounty. com) to help Bitget chase funds
Where to place a question mark
351.6 million is Bitget's own number
At the beginning, the on chain tracker only saw 183 million, and the difference was mainly due to the XRP leg. The tracker focused on Ethereum and couldn't see the XRP Ledger
No one has verified what is inside the 464 million yuan protection fund. The Chinese announcement reads' over 400 million ', which does not match the English one of 464 million
Analysis suggests that the transaction involves three hot wallets and one cold wallet, which contradicts the official statement that 'all cold wallets are secure'
The attribution of North Korea is much stronger in the evidence chain than simple IP matching, but law enforcement and security companies have not yet released formal technical reports
This year, ZachXBT has repeatedly accused Bitget of condoning market makers to manipulate supply, but Bitget denies it
Industry Location
DeFiLlama listed this as the largest theft of 2026, surpassing Liquid Network's 320 million in September and Drift's 295 million in April
From 2026 to present, a total of approximately 2.2 billion US dollars have been stolen
Next, let's look at three things:
When will withdrawals resume
The 24-hour report (which was supposed to be sent before 05:30 Beijing time on September 26th) clearly states whether the entrance has been identified, whether the third-party tool has been named, and whether the 67982 ETH exchanged has been deposited into Tornado Cash
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink