安全客•September 29, 2026•🇨🇳Translated from Chinese

Bitget Loses $351 Million in Record 2026 Crypto Theft After Attackers Forge Internal Transfers

Bitget suffered a $351 million theft from its hot and warm wallets on September 24, becoming the largest known crypto heist of 2026. Attackers bypassed private-key theft entirely by forging internal transfer approvals that passed the exchange’s existing workflow checks.

The incident began at 18:31 UTC when security systems flagged unauthorized transfers. By the following morning, roughly $351 million had left the platform across at least five blockchains. The single largest asset taken was approximately 103 million XRP, valued at about $157 million at the time.

After the funds were moved, the attackers quickly swapped them on decentralized exchanges. One newly created wallet spent nearly $20 million within six minutes while paying a 5 % premium, a classic money-laundering pattern executed under time pressure.

Bitget CEO Gracy Chen stated that the exchange holds a $464 million user-protection fund large enough to cover the entire loss. Customer balances remain accurate, deposits and trading continue normally, and only withdrawals have been temporarily frozen.

Technical analysis shows the attackers never obtained private keys. Instead, they submitted fabricated internal transfer requests that the approval system accepted. This “forged withdrawal slip” approach exploited weaknesses in human and process controls rather than cryptographic protections.

Gracy Chen directly linked the operation to North Korean actors, citing matching IP addresses, VPN preferences, behavioral patterns, and on-chain signatures consistent with previous campaigns. The same group is believed responsible for the $1.4 billion Bybit theft in February 2025.

Industry data from Chainalysis and TRM Labs indicate that North Korean-linked thefts accounted for three-quarters of all crypto stolen globally in 2026. The Bitget incident underscores that even air-gapped cold wallets cannot protect against compromised internal approval processes.

Security experts recommend four immediate improvements: mandatory dual-person review with hardware-bound approvals, context-aware anomaly detection for large or unusual transfers, continuous validation of multi-factor tokens, and routine engagement of third-party investigators such as Mandiant and SlowMist.

Related articles

Habr•Crypto & Financial Crime

Address Substitution Attacks Exploit Partial Address Checks in Crypto Wallets

Address poisoning, clipboard hijackers, and supply-chain malware all rely on users verifying only the first and last few characters of long blockchain addresses. Researchers detail real incidents including a May 2024 theft of 1,155 WBTC worth roughly 68 million dollars where an attacker poisoned transaction history after a test transfer. Studies from Carnegie Mellon University show that even security-conscious users miss mismatches in truncated addresses 21 to 38 percent of the time. Existing identicons such as Jazzicon and Blockies can be matched by attackers because they depend on only the first eight hex characters. The team released the open-source Humanized Hash library that renders any address or hash as a 4x4 grid of colored shapes using PBKDF2 stretching, making forgery computationally expensive. Calculations indicate that matching both the visual pattern and edge characters requires tens to millions of GPU-years on current hardware. The library supports multiple languages with identical output and carries an MIT license with a fixed algorithm.

Habr•Crypto & Financial Crime

Monero Web Wallet Built on Official monero-wallet-rpc Adds Digest Authentication, Two-Phase Transfers and BigInt Precision

A developer created a non-custodial Monero web wallet that runs entirely on the user's machine and communicates only with a personal monero-wallet-rpc instance. The project retained all key-handling logic inside the official RPC daemon while adding a custom backend, frontend and supporting infrastructure. Eight practical challenges were documented, including HTTP Digest authentication that is tightly coupled to TCP connections and the silent loss of monetary precision caused by JSON.stringify on large numbers. The solution introduced two-phase transaction submission to reduce the risk of broadcast errors and replaced floating-point arithmetic with BigInt to guarantee exact handling of Monero amounts. The resulting implementation demonstrates how to expose a convenient web interface without introducing custodial risk or weakening the security model of the Monero wallet RPC.

安全客•Crypto & Financial Crime

Liquid Network Federation Wallet Drained of 4000 BTC in Alleged White-Hat Exploit Exposing L-BTC Minting Flaw

On September 7, the Liquid Network sidechain suffered a major incident where its Federation wallet lost approximately 4000 Bitcoin, worth around $320 million or 2.1 billion RMB, leaving only 200 BTC behind. The funds were moved through the authorized SideSwap settlement platform using PAK keys without any reported key compromise. Liquid officials described the actor as a claimed white-hat hacker intending to return assets for a fee, but security experts point to a critical vulnerability allowing unauthorized L-BTC minting that could bypass the 1:1 Bitcoin backing mechanism. The network has halted all new transactions while federation members work on remediation, affecting major platforms including BTSE, Bitfinex, and BitMEX. This event aligns with a broader 2026 trend where attackers target protocol-level asset issuance rather than individual keys, as seen in recent Coldcard RNG flaws and other incidents totaling $972 million in crypto thefts. The case underscores weaknesses in multi-signature federation validation and cross-chain anchoring that go beyond traditional smart contract bugs.

安全客•Crypto & Financial Crime

1755 Bitcoin Worth $110 Million Stolen from 5000 Hardware Cold Wallets Due to Flawed Random Number Generator

A mainstream hardware cold wallet suffered a systemic defect in its random number generation algorithm, allowing attackers to compromise approximately 5000 wallets and steal 1755 BTC valued at around $110 million. The incident, confirmed on August 4, marks the largest hardware wallet security breach in crypto history because the flaw existed at the foundational level of private key generation rather than in network defenses. Victims had relied on the common assumption that offline cold storage provides ultimate protection, yet the non-random RNG reduced the effective keyspace dramatically, enabling feasible brute-force attacks. Historical precedents show similar RNG weaknesses have repeatedly undermined wallet security across platforms including Android implementations and various hardware chips. The event underscores that cold storage security depends entirely on correct implementation of cryptographic primitives at every layer, from hardware entropy sources to firmware. Experts recommend avoiding blind trust in any single device, verifying third-party audits, and diversifying storage across multiple solutions including open-source options.