In February 2025, cryptocurrency exchange Bybit suffered what remains the largest single crypto theft in history. Attackers drained approximately $1.5 billion in Ethereum and related assets from a cold wallet in a matter of minutes. U.S. authorities, including the FBI, and multiple blockchain analytics firms publicly attributed the attack to the Lazarus Group, a North Korea-linked cyber actor. Bybit later filed a civil lawsuit against North Korea, its Reconnaissance General Bureau, and the Lazarus Group, securing asset freezes while recovering only a small fraction of the stolen funds.
Just over a year later, on September 24, 2026, another major exchange was hit. Bitget detected unauthorized transfers totaling between $351.6 million and $387.5 million from its hot and warm wallets. CEO Gracy Chen stated that the methods appeared “highly consistent” with known North Korean patterns, based on IP behavior and on-chain analysis. Private keys were not compromised; instead, attackers exploited a backend system to spoof transfer data. Bitget confirmed that its User Protection Fund, holding more than $464 million, would fully cover customer losses. Withdrawals were temporarily suspended and are expected to resume gradually between September 28 and October 2, 2026. Customer balances remained unaffected.
Blockchain investigators later reported that the attacker moved roughly $83 million worth of stolen XRP from holding wallets, while approximately $75 million remained in addresses that cannot be frozen under XRP Ledger rules. Exchanges can blacklist receiving accounts, but the attacker’s own wallets cannot be blocked. Circle and Tether froze a relatively small amount—about $320,000—in related stablecoins.
These two incidents form part of a broader pattern. Analytics firms such as Chainalysis, Elliptic, and TRM Labs have repeatedly identified North Korea as the dominant source of stolen cryptocurrency value in recent years. The Bybit heist alone accounted for a significant share of the country’s reported crypto thefts in 2025. The Bitget breach pushed North Korea’s cumulative haul past $1 billion for 2026, according to Elliptic.
The scale of these losses raises persistent questions about the security of centralized exchanges that hold billions in customer assets. While both Bybit and Bitget emphasized that user funds were protected by their reserves or insurance-like funds, the repeated targeting of large platforms highlights ongoing risks. Recovery rates remain low: only a small percentage of the Bybit funds have been frozen or returned, and tracking the Bitget proceeds continues as assets move across chains.
Industry observers note that such high-value thefts are widely viewed as revenue-generating operations linked to state-directed actors. The phrase “General Jin making moves again,” circulating in some online discussions, reflects speculative commentary tying these events to North Korean leadership. Official attributions, however, remain focused on the Lazarus Group and related clusters rather than any single individual.
As investigations into the Bitget incident proceed and on-chain tracking continues, the crypto sector faces renewed pressure to strengthen wallet infrastructure, multi-party approvals, and real-time monitoring. The financial impact on the two exchanges has been mitigated by their protection funds, but the broader message is clear: when platforms of this size are compromised, the consequences extend far beyond a single balance sheet.