Home › Intelligence › Brief
BREACH BRIEF🔴 Critical Breach

North Korean Hackers Steal $387.5 M from Bitget Exchange, Prompting Withdrawal Pause

Bitget disclosed that state‑linked attackers breached its wallet infrastructure, siphoning $387.5 million and forcing a temporary withdrawal freeze. The breach underscores the importance of robust access‑control and transaction‑authorization controls for audit readiness.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 bleepingcomputer.com
🔴
Severity
Critical
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
bleepingcomputer.com

North Korean Hackers Steal $387.5 M from Bitget Exchange, Prompting Withdrawal Pause

What Happened — Bitget, a major cryptocurrency exchange, confirmed that attackers breached its wallet‑backend infrastructure, spoofed transaction data, and moved roughly $387.5 million from hot and warm wallets. The exchange halted all Bitcoin withdrawals, later resuming them after patching the exploited vulnerability and reinforcing its transaction‑authorization controls.

Why It Matters for Trust & Control Assurance

  • The incident illustrates a failure of transaction‑authorization and access‑control safeguards that continuous‑control programs are designed to monitor, test, and evidence.
  • Demonstrates the need for defensible audit trails of privileged actions on wallet‑management systems, a core control objective across NIST CSF 2.0 and other frameworks.
  • Highlights how real‑time detection and rapid remediation of backend flaws are essential to maintain a trustworthy financial‑service posture.

Who Is Affected – Cryptocurrency exchanges and other digital‑asset platforms that manage hot/warm wallets; their customers’ funds and market confidence.

Recommended Actions –

  • Conduct an immediate review of wallet‑admin access rights and enforce least‑privilege principles.
  • Implement multi‑factor authentication and cryptographic signing for all transaction‑initiation processes.
  • Deploy continuous monitoring of privileged actions and maintain immutable logs for audit readiness.
  • Validate that incident‑response playbooks cover transaction‑spoofing scenarios and test them regularly.

Source: BleepingComputer

Technical Notes – Attackers exploited a backend vulnerability that allowed them to spoof transaction data, bypassing the exchange’s authorization checks. The breach affected Bitcoin, Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, Base, and related tokens. No personal data was reported as compromised; the loss was purely financial.

📰 Original Source
https://www.bleepingcomputer.com/news/security/bitget-resumes-bitcoin-withdrawals-after-3875-million-crypto-heist/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →