Skip to content
credential-theftvulnerability

Lazarus stole $351 million from Bitget in September 2026

2 min read
Share

Lazarus stole $351 million from Bitget in September 2026

North Korea's Lazarus Group has stolen over $351 million from Bitget, a major cryptocurrency exchange, in the largest single crypto theft attributed to the group in 2026. The incident follows the pattern Lazarus has used across multiple exchanges over the past three years: sophisticated social engineering or supply chain compromise targeting exchange employees with privileged access.

What happened

Bitget disclosed the breach in September 2026 after on-chain analysis by blockchain security firms traced approximately $351.6 million from Bitget wallets to addresses associated with prior Lazarus laundering operations. The group's laundering infrastructure typically moves funds through multiple chains, crosses through mixing services, and then converts to fiat through jurisdictions with limited law enforcement cooperation. Lazarus has used this playbook consistently since the 2022 Ronin Bridge theft.

Lazarus's crypto theft pattern

Lazarus is responsible for more documented cryptocurrency theft than any other state-sponsored actor. The group operates a well-documented cycle: identify exchange employees with privileged access to hot wallets or infrastructure credentials, deliver targeted lures through fake LinkedIn job offers or direct messaging, compromise the employee's device through trojanized trading tools or job-offer documents, escalate to exchange infrastructure, and execute a rapid transfer before detection. The stolen funds are used to fund North Korea's weapons program. The US Treasury's Office of Foreign Assets Control has repeatedly sanctioned Lazarus-linked wallets and laundering infrastructure.

What exchanges should do

The consistent pattern across Lazarus exchange compromises points to specific controls. Social engineering of employees with privileged access to hot wallets is the primary initial vector. Controls that reduce this risk include mandatory hardware security keys for all privileged accounts, time-delayed withdrawals above threshold amounts, multi-party authorization for large transfers, and behavioral analytics on unusual access patterns from privileged accounts. Architectural controls include strict segregation between hot and cold wallet infrastructure and limiting the fraction of total funds held in internet-connected hot wallets. US-based exchanges should also review their OFAC compliance programs: on-chain analysis tools can flag incoming deposits associated with sanctioned addresses before they are accepted.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you want to talk through how to harden your exchange or digital asset platform against nation-state threat actors.