Chainalysis published its findings on October 1, attributing the $387 million Bitget exchange theft of September 24 to North Korea-linked actors, and said crypto stolen by such groups in 2026 has now passed $1 billion. The breach remains the largest exchange hack reported this year.
Bitget first reported the loss at $351.6 million, then revised the figure upward to around $387.5 million after adding Zcash and Tron balances left out of the initial count. The attackers never obtained private keys. Instead, they compromised a backend system that processes withdrawals, spoofing transaction data so the exchange’s own authorization layer approved fraudulent payouts as if they were legitimate user requests. Cold wallets and hot wallets were not directly compromised in the way older breaches of this scale tended to be.
Where the money went
The stolen funds did not stay in one place for long. Chainalysis’s tracing shows the $387 million moved across Ethereum, taking 49.7 percent of the flow by value in the first hours, XRP at 40.8 percent, Zcash at 7.6 percent and Tron at 1.8 percent. Funds continued to move across networks using cross-chain liquidity protocols to convert XRP into Bitcoin, laundering tens of millions of dollars over roughly a day and a half.
XRP was the single biggest casualty in dollar terms at the start. Roughly 103 million XRP, worth about $157 million when it left the exchange, made up the second-largest share of the theft, split across 23 distinct transfers in the opening hours. Nothing about that movement was subtle. The only reason it held together was the speed with which funds crossed chains. By the time a monitoring system on one network flagged a transaction, the funds had already been bridged to two other chains and split into smaller tranches.
Lookonchain tracked the EVM-chain proceeds separately and reported that the attacker had already swapped most of them into about 67,982 ETH before Bitget finished its internal count. That rapid conversion made freezing harder, since Ether sits in a different set of monitoring and compliance frameworks than the XRP-ledger assets that left first.
How the investigation moved so fast
Chainalysis said its investigators used in-house AI and custom automation to keep up with laundering that would otherwise have outrun manual analysis. The firm reported that automated bridge reconciliation compressed what its own team estimated as more than 20 hours of manual tracing into under 10 minutes of machine work, freeing its analysts to review outputs and direct the investigation rather than trace every hop themselves.
The firm stressed that the automation did not replace investigators. Analysts defined the tracing logic, reviewed what the tools produced, and submitted their work product to compliance teams and law enforcement. Live address labels were pushed to exchanges and police as the investigation progressed, an approach the team said had become standard handling for multi-chain thefts through 2026.
The useful takeaway for exchanges and compliance teams is that speed now matters more at the detection stage than it did two years ago. A laundering chain that once took days to unwind can now move through five bridges in an hour, and the only reliable defense is to freeze addresses before the second hop completes. Chainalysis declined to describe which specific exchanges frozen addresses on its alert list still hold Bitget funds, citing the ongoing investigation.
Why this attack was different
Most prior exchange breaches of this scale have come down to stolen keys. The Bitget theft, in contrast, targeted the systems that decide whether a withdrawal looks legitimate, corrupting the approval process instead of cracking the vault. Bitget’s CEO, Gracy Chen, said during a three-hour livestream on X after the attack that her team suspected North Korean attackers had exploited a backend wallet infrastructure flaw, making fraudulent withdrawals appear to be normal user traffic.
Bitget’s security systems caught the breach at 18:31 UTC on September 24. Within an hour, internal teams had traced roughly $183 million in stablecoins and other assets leaving hot wallets to addresses nobody at the exchange recognized. Law enforcement became involved within the first 24 hours, and several of the largest stolen positions have since been flagged across multiple exchanges.
The total loss estimate kept moving. Bitget added Zcash and additional Tron balances that were missing from its first official count, lifting the figure from $351.6 million to about $387.5 million. No further revision has been announced since October 1. Chainalysis’s figure of $1 billion stolen by North Korea-linked actors in 2026 counts this breach along with smaller thefts across exchanges, bridges and DeFi protocols over the first nine months of the year.
What it means for exchanges
The uncomfortable lesson for operators is that approval systems are attack surface in their own right. Treating private key custody as the only security boundary leaves an exchange blind to a whole class of compromise. Bitget has not published the details of what was exploited, only that the flaw sat in backend wallet infrastructure rather than in the client-side code users touch directly.
2026 is already a record year for crypto theft by North Korean-linked actors. Passing $1 billion puts pressure on every exchange that handles cold storage to describe its backend withdrawal approval path as part of its threat model, something most disclosure documents currently treat as an internal matter. Chainalysis said the investigation continues, with teams monitoring linked addresses and following funds across chains as they move.
For traders, the practical reminder is that hot wallet insurance does not always apply when approval systems rather than keys are compromised, making recovery more likely to depend on law enforcement coordination than on exchange compensation schemes.Sources: Chainalysis blog, October 1, 2026; Fortune, September 25, 2026; Gizmodo, September 2026; CryptoRank and CryptoBriefing coverage of the Chainalysis report.
