Bitget Hack Grows to $387.5M, Tied to North Korea
Bitget just pushed its September 2026 hack estimate up to about $387.5 million (USD), far above its first figure. The jump matters because it shows how slippery stolen crypto totals can be, and how easily attacker funds slide past exchanges before anyone notices.
What actually happened
On 25 September 2026, Bitget raised its estimate of funds moved to attacker wallets from about $351.6 million (USD) to roughly $387.5 million (USD), according to Wu Blockchain. The exchange said the increase came from updated accounting on Zcash and TRON transfers, not a fresh breach, and that partners had helped freeze some funds. Elliptic called the attack 'highly likely' linked to North Korea, pointing to wallet overlaps with earlier state-linked thefts. For comparison, the FBI blamed North Korea for the $1.5 billion (USD) Bybit theft in February 2025. zeroShadow found more than $1 billion (USD) of those Bybit funds laundered between February and June 2025, and Elliptic traced roughly $200 million (USD) of it through the exchange service eXch.
How we got here
The Bybit theft set the template investigators now use on Bitget. Both zeroShadow and Elliptic found that middlemen, not the original hackers, usually handle most laundering. Chainalysis reported in September 2026 on the Xinbi merchant network, which took traceable stolen crypto and handed back a separate batch of stablecoins already blended with proceeds from unrelated scams. That swap lets attackers step away from the dirty coins early. Funds tracked on public ledgers may already have changed hands, with intermediaries taking on freeze risk in exchange for paying hackers a smaller, cleaner sum upfront.
Why this matters for you
For everyday wallet users, the lesson is simple: a hack's first headline number is rarely final, and totals can climb weeks later. For anyone using smaller exchanges or OTC desks, this case shows laundering networks can mix dirty stablecoins into normal-looking transfers. Builders of wallet or payment tools may need stronger screening, since clean-looking funds can still trace back to crime. Within the bonuz ecosystem, it underscores why counterparty checks matter before connecting to any exchange or swap service.
The bigger question
If blockchain analysts can trace stolen funds this precisely, why does getting them back still depend on exchanges, token issuers, and police in different countries choosing to cooperate quickly? Mapping where money moved is no longer the hard part. Turning that map into frozen or returned funds still is. Until international coordination catches up with on-chain tracing, thefts of this size may keep moving faster than the systems meant to stop them.
What to watch
Bitget has not released a full technical report on the breach. Elliptic's North Korea link remains an assessment, not confirmed fact. Watch for updates on how much of the $387.5 million (USD) gets frozen, and for further US Department of Justice action following its earlier seizure of over 15 million USDT. bonuz.market will keep watching how these laundering networks affect everyday crypto users.






