
Three-quarters of all crypto stolen this year has one suspected source: North Korea. Let that sink in. According to blockchain intelligence firm TRM Labs, that figure isn’t an exaggeration. And now, with more than $351 million drained from cryptocurrency exchange Bitget in a single attack, it’s becoming impossible to treat state-sponsored crypto theft as a niche problem.
As TechCrunch reported, the breach happened Thursday and involved the unauthorized transfer of funds from Bitget’s hot wallets. Those are wallets connected to the internet, kept online for active trading purposes. They are, by design, more exposed than cold storage. The exchange has since suspended all crypto withdrawals across its network, with no word yet on when that restriction will lift.
Bitget CEO Gracy Chen described the attack as “highly consistent with known patterns of North Korean hacker organizations.” That’s a specific claim, and it matters. North Korean hacking groups have been tied repeatedly to crypto theft campaigns, with the suspected goal of financing the country’s weapons program. This isn’t opportunistic crime. It’s systematic, well-resourced, and state-directed.
For users, the immediate question is what happens to their money. Bitget says it holds $464 million in a user protection fund, enough to cover the $351 million loss. That’s reassuring on paper, but it raises a harder question: why were that many assets accessible in hot wallets at all? Hot wallets are a known risk. Keeping large sums in them is a calculated gamble, and this time the exchange lost.
This attack is now the largest crypto theft of 2026, edging past a $340 million hack from September. That earlier incident had an unusual ending: the attacker returned most of the funds, keeping only $47 million. Don’t expect the same outcome here. North Korean-linked groups don’t return money. They launder it, slowly, through mixers and chain-hopping, to fund a government that has few other reliable revenue streams.
The bigger picture is grim. The crypto industry keeps building faster than it secures itself. Hot wallets, centralized exchanges, and open source software supply chains are all known attack surfaces. North Korean groups have exploited all three. Until exchanges treat security with the same urgency they bring to user acquisition, these headlines will keep coming. And users will keep paying the price.