Bitget's chief executive said a $388 million theft from the exchange exploited a vulnerability in third-party security infrastructure, according to the company's statement. Investigators are assessing whether North Korean threat actors carried out the attack, though attribution remains unconfirmed.
The breach marks one of the largest exchange compromises since the FTX collapse in November 2022. Circle and Tether have frozen approximately $318,000 in stolen stablecoins across their networks, but Bitget has not disclosed total asset recovery figures as the investigation continues.


Bitget operates as one of the largest derivatives exchanges by open interest, with a user base exceeding 20 million accounts as of mid-2026. The company offers spot and perpetual futures trading and holds customer assets in both self-custodied and third-party managed wallets. The CEO said attackers gained access through a flaw in external security systems rather than through Bitget's core infrastructure.
Investigators have observed the attacker conducting small test transfers before executing the full theft, a pattern consistent with reconnaissance common to high-value exchange breaches. The threat actor spent time probing Bitget's risk controls and transaction monitoring before moving the full amount.
North Korean-linked groups have targeted cryptocurrency infrastructure repeatedly since 2021, with security researchers attributing over $600 million in annual theft volume to state-sponsored actors from Pyongyang. The Lazarus Group and affiliated units have focused on exchanges, bridges and custodial platforms to acquire foreign currency and bypass international sanctions.
Exchanges including Coinbase and Kraken operate primarily on in-house security stacks, though larger platforms like Binance use hybrid models incorporating third-party custody and infrastructure providers. Bitget's reliance on external vendors for wallet management, key storage, and access control created a point of failure outside the company's direct control. The scale of the breach will likely prompt exchanges to audit their vendor risk frameworks and increase the proportion of critical security functions managed in-house.