Bitget disclosed a theft of $351.6 million on September 24, 2026, and in the days since, blockchain investigators have begun drawing a line from the stolen funds to infrastructure previously tied to North Korea's Lazarus Group. What is missing, so far, is any regulator willing to say so on the record.
Analyst Specter surfaced the initial evidence pointing to overlap between the laundering trail and wallets associated with the AFX Trade exchange hack from July 2026, an incident that international intelligence agencies had already linked to TraderTraitor, a suborganization operating under Lazarus. The connection, if it holds, would place Bitget alongside a growing list of exchanges targeted by the same network.
The mechanics of the theft echo an earlier, larger case. Attackers extracted 20 million XRP from Bitget, of which roughly 328,000 XRP crossed the NEAR Intents bridge before landing in an Ethereum address labelled 0xa07f…6feb. Etherscan separately tagged a wallet, 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee, as "Bitget Exploiter 1" on September 25, 2026, noting it received funds from a wallet marked "Bitget 6," moved them within 24 hours, and was then emptied.
Bitget chief executive Gracy Chen said the exchange had found an IP address coincidence with VPN networks associated with North Korean operators. She also pointed to the attack vector itself: withdrawal orders were falsified within Bitget's backend without any exposure of private keys, a method that mirrors the operational model used against Bybit in February 2025, when attackers made off with 400,000 ETH.
A slower response than Bybit
After the Bybit theft, the FBI issued an official statement naming TraderTraitor within five days. Eighteen months on, there has been no equivalent statement for Bitget. The Office of Foreign Assets Control has issued no designation, and neither the US Treasury, the FBI, nor any multilateral body has ruled on the case. The attribution, for now, rests entirely with private analysts and the exchange itself.
The scale of North Korea-linked hacking this year gives the pattern context. TRM Labs data for the first half of 2026 put North Korea-linked losses at 66.2% of global crypto hack losses, around $643 million. The UN Security Council Panel of Experts has estimated cumulative theft by North Korea-linked networks at over $3 billion since 2017.
Bitget has said its User Protection Fund, worth $464 million, stands behind affected users, a buffer larger than the loss itself. But for European exchanges and regulators watching the case, the more pressing question is not whether the fund can absorb the hit, it is why formal attribution, and the accountability that follows it, continues to lag so far behind the forensic trail.




