The alarm tripped at 18:31 UTC on September 24, somewhere inside the Seychelles-based machinery of Bitget—one of the largest crypto exchanges on the planet, founded in 2018, claiming more than 120 million users across 150-plus countries, a self-styled “Universal Exchange”—and within about an hour the blockchain peepers were watching money walk out the door: roughly $183 million in stablecoins, Ethereum and sundry other assets sliding out of wallets tagged as the exchange’s own. Hours later Bitget confirmed the breach at $351.6 million. By the next day the official tally had climbed to $387.5 million, with Zcash and some overlooked TRON balances added to the ledger—a fuller accounting, the exchange said, not fresh theft. DefiLlama now ranks it the largest crypto hack of 2026.

And here is the part that should keep every exchange treasurer awake: nobody stole the keys. “They did not forge user withdrawal requests, nor did they obtain our private keys of the cold wallet and any hot, warm wallet,” CEO Gracy Chen said in a livestream and a string of posts on X. “The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out.” Which is to say: the vault combinations stayed safe. Somebody fed forged paper to the machine that stamps APPROVED, and the machine stamped, and stamped, across parts of Bitget’s hot and warm wallet layers. The cold wallets, sitting offline, were never touched.

The ledger-readers of crypto Twitter were onto it before Bitget said a word. A pseudonymous researcher called DCF GOD flagged a newborn wallet spending $19.67 million in USDT0—a cross-chain cousin of Tether—to grab 7,111 ETH in six minutes, paying roughly 5% over market through UniswapX and 1inch Fusion, the kind of hurry money only makes when it isn’t yours. More Bitget-tagged wallets hemorrhaged across at least five blockchains. Lookonchain’s inventory reads like a pawnbroker’s fever dream: 102.93 million XRP, about $157.48 million, the single biggest slice; 31,890 ETH ($85.75 million); 34.75 million USDT; 21.05 million USDC; 3,000 XAUt of tokenized gold ($12.82 million); 12,719 BNB; 821,012 AVAX; 20.59 million TRX—most of the EVM-chain loot already consolidated into 67,982 ETH. Arkham Intelligence has tagged the attacker’s wallet.

Bitget’s answer is a very large check written to itself. Chen told customers their balances remain accurate and the entire loss sits inside the exchange’s User Protection Fund—a war chest of more than $464 million, 5,500 bitcoin, built years ago for exactly this scenario and worth $300 million back in 2023. Covering $387.5 million would eat most of a reserve whose dollar value floats with the bitcoin price. Deposits and trading never stopped; only withdrawals froze, pending a plan the exchange promised by 4:00 AM UTC on September 26. Mandiant and SlowMist are running the forensics, a full root-cause report is pledged, and Bitget Wallet—the self-custodial app—sits on “completely separate and independent infrastructure” and was not affected, the company said.

Now, the suspect. Chen went live and pointed north. “We’ve identified some IP addresses that match the VPN choices by a certain DPRK group,” she said, adding that “the pattern looks very much like what the North Korean team did before.” Carefully lawyerly pointing: no unit named, identity unconfirmed, no technical evidence made public, and Bitget does not currently believe it was an inside job. But Elliptic assessed the attack as “highly likely” North Korea-linked, citing on-chain ties between the stolen XRP and ether from an earlier DPRK-attributed theft, plus Bitget proceeds brushing addresses used to launder last year’s $1.4 billion Bybit heist. MetaMask’s Taylor Monahan traced Bitget loot into an address that had already received Bybit stolen funds and named Lazarus outright; investigator ZachXBT called it “the Bitget exploit by DPRK.” Chen added a flourish of her own: the same crew, she says, once lifted about $80,000 from her personal wallet.

Lazarus—tracked also as TraderTraitor, state-backed crews that U.S. officials place under the regime’s military intelligence services—is the industry’s resident ogre. The FBI confirmed the $1.4 billion Bybit job as North Korean work. Chainalysis counts at least $2.02 billion stolen by North Korean hackers in 2025 alone, $6.75 billion all told; TRM Labs reckons DPRK agents accounted for 76% of stolen crypto value through April; Elliptic says Bitget is the largest single suspected North Korean theft of 2026 and pushes the regime’s take this year past $1 billion. There was also the six-month social-engineering courtship of Drift that ended with about $285 million gone in 12 minutes.

Pyongyang’s official position on all of this: a “non-existent” cyber threat, peddled by “U.S. government organs, reptile media organs and plot-breeding organizations.”

The cavalry, such as it was, arrived Friday at 05:00 UTC, when Circle blacklisted an address labeled “Bitget Exploiter 8,” freezing 99,990 USDC at the contract level; roughly seven hours later a Tether multisig signer followed, locking 218,023 USDT. Total recaptured: about $318,000, against $387.5 million gone. The wallet’s roughly 170 ETH sat untouchable, because issuers can freeze their own tokens and no issuer on earth can freeze Ethereum—precisely why the thief sprinted to convert, and why other exploiter addresses still hold 63,000-plus ETH beyond anyone’s authority. Chen has posted a bounty—5% for voluntarily freezing attacker funds, 5% for recovery—plus a tracing dashboard and leads routed through Bybit’s Lazarusbounty site, and says some blockchain foundations have already frozen hacker wallets. Circle, criticized in the past for sitting on its hands in these episodes, moved fast this time. The freeze also renewed the old debate about the centralized kill switches hidden inside supposedly permissionless money.

Context, because the ledger keeps bleeding: April was already the worst month on record for the number of crypto project hacks—DefiLlama counted 29 incidents, Certik put losses near $651 million—and CryptoSlate noted that September has now passed it as the costliest month of 2026. A bug in Blockstream’s Liquid Network software let attackers mint unbacked L-BTC and cash out roughly 4,000 bitcoin, then worth about $320 million, without stealing the federation’s keys; a Coldcard hardware-wallet flaw had already been exploited for more than $100 million. OpenZeppelin co-founder Manuel Aráoz has told friends and family to exit DeFi altogether, blue chips included, because “coding agents are superhuman at finding vulnerabilities.”

Meanwhile, in the NFT attic

The same Friday, Magic Eden warned that the ghosts of its own past were picking pockets. NFTs listed on its long-closed EVM marketplace between roughly February and October 2024 sat exposed to a bug in Payment Processor V2, a trading contract built by Limit Break, which Magic Eden adopted in 2024, abandoned that October and buried entirely when it shut its EVM operation in early 2026—having dropped Ethereum and Bitcoin support in February to focus on Solana and its crypto casino, Dicey. “No live Magic Eden listings were impacted in this exploit,” the company said; the danger lives in old “approved for all” permissions, which never die until revoked.

At 9AM EST, according to Yuga Labs VP of blockchain 0xQuit, somebody used the bug to lift 10 Meebits, 50 Otherdeeds, 10 World of Women and 235 Desperate ApeWives. Limit Break could pause the newer V3—same flaw—but V2 could not be stopped, so came a whitehat scramble: friendly hackers racing the unfriendly ones to move 23,155 NFTs, “worth north of $5.7M USD,” to safety, reclaimable once owners revoke the approvals. Some 660 WETH didn’t make it out. The advice: revoke V2’s permissions on Ethereum, Polygon and Base via Revoke.cash—knowing that revocation brings back nothing already gone.