BITGET EXCHANGE HACKED IN 2026 4th of October, 2026
On the 24th of September 2026, Bitget exchange was hacked. Bitget is a major cryptocurrency exchange. Bitget suffered a massive cyberattack resulting in the theft of approximately $387.5 million in digital assets. The incident marks the largest crypto hack of 2026.
According to investigations by cybersecurity firms Mandiant and SlowMist, the hackers executed a sophisticated supply chain exploit. The Attackers targeted a third-party security product using a zero-day vulnerability to harvest privileged internal credentials. Then instead of stealing the exchange’s private keys, the hackers used these credentials to inject spoofed transaction data directly into Bitget's wallet backend infrastructure. This tricked the platform's auto-signing authorization process into legitimate-looking, unauthorized withdrawals from hot and warm wallet layers. As a result of this, Funds were drained across 11 different blockchains, primarily compromising Ethereum (ETH) and XRP, alongside quantities of BNB, Solana-based assets, USDT, and USDC. Bitget's offline cold wallets remained completely untouched.
After intelligence gathering was conducted, Blockchain intelligence firm Chainalysis and security researchers have officially attributed the heist to North Korea-linked actors (such as the Lazarus Group). The thieves rapidly moved assets across decentralized bridges. Notably, they used THORChain for cross-chain swaps—which denied Bitget's request to freeze the funds, citing permissionless architecture—and funneled millions into Zcash’s privacy-centric "Ironwood" shielded pool to hide the trail. (As of 4 October, 2026)Only about $1.1 million has been successfully frozen via cooperative efforts with Tether, Circle, and NEAR Intents. .
.
.