over:heard
Unclaimed brand page — independent analysis by over:heard, based solely on public coverage.
Bitget logoBBitgetbitget.com

Bitget says hackers forged transfer records, with CEO pointing to North Korea

AssessmentTHREATSeverityHIGHEscalation riskHIGHUrgencyHOURS
Analysis as of 2026-09-26 — a dated snapshot of the coverage verified that day.
Evidence-backed — 25 verified facts from 9 sourcesBCTNBF+3View evidence ›

Executive summary

Bitget experienced a major security breach on September 24, 2026, with attackers siphoning approximately $387.5 million from its hot- and warm-wallet environment.1423 The company has stated the attack involved forged transaction records that tricked its internal approval system and has preliminarily linked it to North Korean state-backed hacking groups.1012 Bitget has taken immediate containment actions, including pausing withdrawals, and has committed to using its User Protection Fund to absorb the loss, ensuring all user funds remain safe.5813 The breach represents a preventable crisis due to a failure in the company's duty of care for customer asset security, requiring a rebuild strategy focused on transparency and restoring trust.212

Mentions (4)

Show 2 moreShow less

Risks / opportunities

THREATLoss of customer trust and potential mass withdrawals if users doubt platform security or recovery ability.513
THREATRegulatory scrutiny and potential sanctions due to the scale of loss and attribution to a North Korean hacking group.1023
THREATLong-term reputational damage as a 'hacked' exchange, affecting user acquisition, partner relations, and token value.18
OPPORTUNITYDemonstrating robust crisis management and customer commitment through the User Protection Fund can strengthen loyalty among existing users.8

Best response strategy

REBUILD The breach resulted from a compromise of Bitget's internal wallet infrastructure used to forge transaction approvals.12 Stakeholders will assign blame to Bitget for this security failure despite the external attribution to North Korean actors.10 Bitget's immediate actions to pause withdrawals, contain the loss, and commit to covering user funds must be followed through with full transparency and corrective action.5821

Who is watching, and what each expects from the response:

customersSafety of their funds, timeline for restoring withdrawals, and transparency of Bitget's investigation.51320
investorsFinancial impact of the $387.5 million loss, volatility of BGB token, and long-term reputational damage.1823
regulatorScale of breach, attribution to North Korean state actor, and Bitget's compliance with security standards.10
mediaTechnical details of the attack, North Korean link, and Bitget's response narrative.1012
partnersStability and security of Bitget's infrastructure for ongoing integrations.22

Suggested response plan

T+0-4h
Phase 1 — Contain & verify
Outcome: A unified internal command is established, all public-facing teams are armed with the approved narrative, and the technical investigation is coordinated.921
executive
Convene the cross-functional crisis team to establish a single source of truth, audit all customer-facing communications, and task security with producing a preliminary technical brief.9
  1. Draft and distribute an internal memo freezing uncoordinated external communication.
  2. Brief customer support with a script confirming user fund safety and directing to official updates.
  3. Task security leads with compiling initial findings on root cause for comms review.
Done when: Zero uncoordinated external communications from Bitget staff for 4 hours and the customer support script is deployed.
T+4-12h
Phase 2 — Respond
Outcome: A detailed public statement is published, directly notifying key stakeholders, and the promised hourly update cadence is initiated.925
comms
Publish the detailed incident statement on Bitget's website and social channels, send a direct email notification to all users, and schedule spokesperson availability for crypto media.
  1. Finalize and publish the public statement on the Bitget website blog and Twitter/X account.
  2. Queue and send a direct email to all registered users with the statement and FAQ link.
  3. Schedule a background briefing for two pre-vetted crypto trade publications.
Done when: The statement is live on the website and social channels, the user email is sent, and the first media briefing is confirmed.
“Bitget experienced a security incident on September 24, 2026, involving unauthorized transfers from parts of our hot- and warm-wallet infrastructure.14 We have confirmed the outflow has stopped.21 The preliminary loss estimate is approximately $387.5 million.23 All user funds are safe and will be covered in full by our User Protection Fund, which stands at more than $464 million.1387 Our investigation, aided by external blockchain analysts, has preliminarily linked the intrusion to North Korean state-backed hacking groups based on technical evidence.10 The attackers compromised a backend system to forge transaction data, tricking our internal approval process.12 Customer balances remain accurate, and trading and deposits continue normally.1522 Withdrawals are temporarily paused pending a full security review.520 We are committed to hourly updates on our status page and will publish a detailed incident report within 24 hours covering the root cause, affected systems, and our corrective actions.9 We plan to announce the timeline for restoring withdrawals by September 26.25 We have also launched a Recovery Bounty Program.24”
website statementsocial mediadirect outreach
T+12-24h
Phase 3 — Manage
Outcome: The detailed incident report is published, withdrawal restoration timeline is communicated, and proactive outreach to regulators and partners is completed.925
legal
Publish the 24-hour incident report, announce the withdrawal restoration plan, and initiate formal notifications to relevant financial and cybersecurity regulators.
  1. Publish the promised detailed incident report on the Bitget website.
  2. Update the website status page and social channels with the specific timeline for restoring withdrawals.
  3. Draft and send formal notifications to relevant regulatory bodies outlining the incident and response.
Done when: The incident report is published, the withdrawal timeline is live, and regulator notifications are dispatched.
T+1-3 days
Phase 4 — Recover
Outcome: Withdrawals are restored, the Recovery Bounty Program gains traction, and a forward-looking 'Security Reinforced' narrative is established in follow-up coverage.2425
operations
Execute the withdrawal restoration, actively promote the Recovery Bounty Program to the crypto community, and pitch 'lessons learned' commentary to industry media.
  1. Technically restore withdrawal functionality according to the published timeline and notify users.
  2. Promote the Recovery Bounty Program across crypto forums and social channels.
  3. Work with comms to pitch op-eds on enhanced security measures post-breach.
Done when: Withdrawals are fully restored, the bounty program receives its first substantive lead, and a major industry outlet publishes a Bitget-authored piece on post-breach security.

Evidence sources (9)

Everything this briefing cites — ANCHOR started the story, CONTEXT backs it without naming the brand.

Are you bitget.com?

Your crisis desk is ready — claim it to respond. Claiming is free — your response strategy & plan become collaborative, and you get the option to display your response & status updates on this page.

Claim your brand

Follow this story

One short, factual update when this story develops — nothing else, from over:heard.

Email updates

By subscribing you consent to receive email updates about this story. Double opt-in: nothing is sent until you confirm from your inbox. Unsubscribe anytime — one click in every email.

Push notifications

No email needed — alerts appear on this device.

Not bitget.com? See what over:heard would flag for your brand. Start free →
Independent media-monitoring briefing compiled by over:heard radar from public coverage. Assessments are decision support — not statements by, or affiliation with, the brands mentioned. · Built from public sources, cited. Every brand has a free, permanent right of reply — editorial policy · Powered by over:heard by wise:able