Chainalysis attributes $387 million from the Bitget hack to North Korea: what matters now for investors in Germany
The analytics firm Chainalysis attributes the theft of around $387 million at Bitget to actors with ties to the DPRK and puts the annual total above one billion dollars. What that means for custody, choice of exchange and record-keeping in Germany.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
The breach at the crypto exchange Bitget of September 24, 2026 now has a sender: in early October the analytics firm Chainalysis attributed the theft of around $387 million to actors with ties to the Democratic People's Republic of Korea. For you as an investor in Germany that attribution changes nothing about your balance, but it does change the risk assessment: anyone who suspects a state-backed team behind an attack expects a series rather than an isolated case. This piece sorts out what is documented, and what follows from it for custody, choice of exchange and record-keeping.
$387 million in 23 transfers: how the Bitget hack unfolded
The attack of September 24, 2026 hit a hot wallet of the exchange, meaning a holding that is permanently connected to the internet and services withdrawals. A hot wallet is the counterpart to a cold wallet, whose keys sit offline. That very reachability makes it a target: whoever controls the keys can transfer immediately.
On Chainalysis's account, around $387 million left the exchange within three hours, spread across 23 individual transfers. Depending on the report the sum is given as $387 million to $388 million; the range comes from different valuation moments for the tokens that were moved. Three hours is a long time in this context. It is enough to spread money across several networks, and it is not enough to freeze it if nobody is watching.
The exchange reacted in stages. Withdrawals stood still at first, after which Bitget says it reopened them step by step from September 28. As cryptoticker.io reported on September 29, 2026, customers pulled out a net total of around $463 million in the days that followed, which is more than the attack itself cost. That is the second damage of a hack, and it hits the exchange, not the attacker.
The attribution to DPRK-linked actors and its limits
An attribution in blockchain forensics is neither a confession nor a court ruling. It is a statement of probability resting on patterns: recurring addresses, known exchange services, typical sequences used in obfuscation, windows of activity. Chainalysis works with a stock of addresses that has grown over years out of investigations, exchange data and its own observations.
What holds up in such an attribution is that money trails can be reconstructed. What holds up less well is any statement about who sat at the keyboard. The analysts' wording therefore stays deliberately cautious and speaks of actors with ties to the DPRK, not of an authority or a person named outright. You should read that caution along with the finding whenever headlines turn an attribution into a fact.
For practical purposes the cautious version is enough. Whether an attacker is state-funded or not changes the probability that the same method resurfaces in three months. State-backed teams work for the long term, with a budget and with patience.
Ethereum, XRP, Zcash and Tron: the four chains in the outflow
The money did not stay in one network. Chainalysis puts the distribution across four chains: 49.7 percent flowed over Ethereum, 40.8 percent over XRP, 7.6 percent over Zcash and 1.8 percent over Tron. That split is not a coincidence but a division of labour.
Ethereum carries the deepest liquidity and most of the decentralised trading venues where tokens can be swapped without opening an account. XRP delivers fast and cheap transfers with short confirmation times. Zcash allows shielded transactions in which the amount and the parties stay hidden in the protocol. Tron is a widely used route for stablecoin movements at low cost.
The Zcash share is the most delicate part of the trail. As early as September 30, 2026, cryptoticker.io described how 2,746 ZEC from this complex moved into a shielded pool. What goes in there cannot be followed any further from outside as long as it stays in. What remains to be watched is the exit: at some point money has to reach an exchange in order to become national currency, and that is where identity checks and anti-money-laundering supervision apply.
To put the orders of magnitude in context: Zcash traded at around $1,336 on Sunday evening, a good 17 percent below the level of the previous week, Ethereum at about $2,706 and XRP at around $1.51, in each case according to CoinGecko. The prices say nothing about the hack; they only show how large the markets were through which the money ran.

Cross-chain bridges and mixers: where the money went after the outflow
After the outflow the second phase begins, the obfuscation. Chainalysis names four tools for it: bridges, cross-chain liquidity protocols, mixers and decentralised exchanges. A bridge is a service that locks a value in one network and releases an equivalent in another. It does not break the trail, but it cuts it into two parts that have to be reassembled first.
A cross-chain liquidity protocol goes one step further. On this account the investigators followed stolen XRP through such a protocol, which paid out Bitcoin at the end instead of sending the tokens straight to an exchange. From a tracing perspective that means: the same money leaves the service in a different currency and in a different network, and the connection consists only in the closeness in time and in the size of the amounts.
A mixer, in turn, pools deposits from many users and pays them out freshly mixed. Decentralised exchanges, finally, swap tokens without any account being opened. None of these tools is forbidden in itself, and each has legitimate uses. Chained one after another they produce a sequence that costs investigators time. It is precisely that time the technical part of the report addresses.
Hardware wallets comparedOne billion dollars in 2026: the tally of DPRK-attributed thefts
With the Bitget case, the sum of crypto thefts that Chainalysis attributes to groups with DPRK ties in 2026 passes the mark of one billion dollars. That figure is an annual total from several incidents, not an assessment of a single attack.
A look at the market as a whole helps to place it. On October 2, 2026 cryptoticker.io reported that losses from crypto hacks in the third quarter of 2026 came to $1.26 billion in total, the highest level of any quarter. A single incident of $387 million accounts for just under a third of that. Concentration of this kind is the more important information for investors than the annual total, because it shows where the risk sits: with large, centrally custodied holdings.
What makes an exchange hot wallet so attractive
An exchange has to be able to pay out at any time. For that it keeps part of its client holdings in wallets whose keys sit on systems reachable online. The larger the exchange, the larger that pot. An attacker who gets inside once reaches more in a single go than they would take in a hundred attacks on individual users. That is the structural reason why exchange holdings are regularly the target of such operations, and no attribution changes it.
AI-assisted tracing cuts bridge matching to under ten minutes
The second notable part of the report concerns the tool, not the perpetrator. Chainalysis states that it deployed an in-house AI automation in order to match transfers across bridges to one another. That matching is manual work: for every entry on one chain you look for the matching exit on the other, via timestamps, amounts and fees. According to the firm, a task that would have taken more than 20 hours shrank to under ten minutes.
That figure comes from the provider itself and cannot be verified from outside. It is plausible nonetheless, because pattern recognition across large volumes of data is exactly the strength of such methods. The consequence is a shift in tempo: obfuscation stays cheap, tracing gets faster. Anyone sending money through five stations now gains hours rather than weeks.
For you this has a tangible side effect. The faster addresses are flagged as tainted, the more likely an exchange is to freeze affected deposits. That also hits users who happened to receive tokens through a decentralised swap that was fed with flagged funds. Anyone swapping larger amounts via unknown counterparties carries that risk too.
What the hack means for a balance held on a crypto exchange
The most important distinction is the one between possession and claim. If your coins sit with an exchange, you hold no keys. You hold a claim against the company. As long as the company works, you never notice the difference. If it fails, its solvency decides whether you get your balance back.
No blanket verdict against exchanges follows from that. Without an exchange there is no way to buy, and for small amounts in constant motion custody there is practical. The question is the size. An amount whose loss would genuinely hurt you belongs in a form of custody where you hold the key. Which devices do that and how the models differ is shown by our hardware wallet comparison with the current terms.
A second point concerns spreading. Several smaller holdings with different providers lower the risk of a single failure but raise the effort for records and fees. There is no solution here without a drawback, only a decision that fits your own sum.

Protection fund, reserves and withdrawal deadlines at Bitget
After the attack, Bitget says it topped its protection fund back up to around $309 million. A fund of that kind is a voluntary reserve held by the company, not a deposit guarantee scheme. There is no statutory guarantee behind it, no claim to compensation and no authority that steps in if it fails. The size of a fund says something about a provider's intention, nothing about an assurance.
Equally important is the question of records. Reserve attestations, often called proof of reserves, show at one point in time that holdings exist. They do not show that no liabilities stand against them. A complete proof would need both sides of the balance sheet and an independent audit. So anyone reading a reserve statement is reading a snapshot.
Crypto exchanges comparedMiCA licence and the BaFin register: the legal framework in Germany
Since the EU-wide transitional period ended on July 1, 2026, every provider delivering crypto-asset services in Germany needs a licence. The basis is the European regulation on markets in crypto-assets, MiCA for short, supplemented in Germany by the Crypto Markets Supervision Act. Which obligations that brings for providers is something our overview of the MiCA licence and its duties sets out.
In practice that means two things. First, there is a register in which you can check whether a company is supervised: BaFin's company database lists licensed institutions and is open to the public. Second, a licence does not mean that a provider is safe against attacks. It means that there are requirements on organisation, own funds and complaint channels, and a supervisor that can intervene.
An attack on an exchange outside this framework has an unpleasant consequence for you: there is no body you can turn to. With a provider licensed in the EU, the regulation sets deadlines for handling complaints. With a provider without a licence, what remains is the route through a foreign court, and for small sums that route is effectively barred.
Self-custody, seed phrase and hardware wallet: holding coins outside the exchange
Self-custody means that you hold the private keys yourself. As a rule a recovery phrase secures it, the seed phrase, usually twelve or 24 words. Whoever has those words has the coins. The whole practice follows from that: the phrase is generated on the device, it is never typed out, never photographed, never stored in a cloud and never entered into a form that asks for it.
A hardware wallet is a device that generates the key and confirms transactions without handing it over. It protects against attacks on your computer and against the failure of an exchange. It does not protect against the loss of the recovery phrase and not against a signature you give yourself on a faked page.
The quiet tax question when you move
Moving your own coins from an exchange into your own wallet is not a sale and triggers no tax in Germany, because there is no disposal. What matters are the records: the acquisition date and the acquisition cost do not travel with them automatically. Anyone who wants to prove the one-year holding period later needs the original statements. So pull the documents out before an account is closed, because after that access to the history is often gone.
Fake job offers as a way in: the second DPRK method
Alongside attacks on exchange systems stands a second method that hits individual users and developers. On September 19, 2026 cryptoticker.io described how malware was distributed via fake job offers and supposed interviews, with which wallets could be emptied. The pattern is always similar: an attractive offer, a file or a code project you are supposed to run locally, and time pressure that cuts the thinking short.
The protection against it is banal and effective. Someone else's code does not run on the machine that holds a wallet. Anyone working with crypto professionally separates the work device from custody. And no serious employer asks for a recovery phrase, a wallet export or a test transfer.
The link to the Bitget case lies in the goal, not in the technique. The same annual total of more than a billion dollars is fed by both routes: the big breach at a custodian and the patient work on individual keys.
Bitget hack: Your next three steps
- Sort the place of custody by size of amount. Decide which sum you leave sitting on an exchange and shift the rest into your own wallet. If you need an exchange with an EU licence as a starting point, you will find the licensed providers in our overview of regulated crypto exchanges.
- Harden access and recovery. Two-factor protection via an app instead of by SMS, your own withdrawal address list and a recovery phrase that exists only on paper or metal. For smaller amounts without a dedicated device, the software wallet comparison shows which apps keep the keys locally.
- Secure your records while you still have access. Pull statements, purchase dates and transfer receipts from every account you shrink or close. A portfolio tracker does this on an ongoing basis; which tools carry the holding period per account is in our overview of crypto tax tools.
The attribution of the theft changes nothing about your holding. It changes the expectation: an opponent with a budget and patience comes back, and the cheapest precaution remains not holding everything in one place. Decrypt described the attribution in detail.
(As of October 4, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Frequently asked questions about the Bitget hack
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Bitget Hack of $351 Million: What to Check at Your Crypto Exchange Now
- $1.26 Billion in Three Months: Crypto Hacks Hit Their 2026 High
- 387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now
- Bitget Withdrawals Resume on September 28: What to Check on a Residual Balance Now
- NEAR Intents Blocks $50 Million From the Bitget Hack: Why THORChain Let the Swaps Through
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
February 21, 2025 9:55 PM

Bybit Hack Revealed: Here's the Mastermind Behind the $1.46 Billion Theft
The Bybit hack has been traced back by the blockchain investigator ZachXBT, with conclusive evidence linking the hackers to the $1.46 billion theft. Full details revealed...
December 26, 2025 1:50 PM

Breaking: Trust Wallet Chrome Extension Hack Drains $7M, Full Reimbursements Promised
A supply-chain attack hit Trust Wallet’s Chrome extension, draining $7M from users. Binance’s CZ says all victims will be reimbursed.
September 25, 2026 4:13 PM

Crypto Exchange Protection Funds Recalculated: What Really Covers Your Balance After the Bitget Hack
The $351.6 million attack on Bitget would eat up three quarters of the exchange's in-house protection fund. We retrieved the protection promises of several exchanges ourselves and measured them against deposit insurance and MiCA liability.
August 13, 2026 4:59 PM

Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.
September 19, 2026 10:11 PM

North Korean Hackers Drain 7,000 Crypto Wallets: What to Check on Job Offers and Coding Tests
Seven agencies, among them Germany's BND and BfV, warn about the WaterPlum group: 30,000 infected machines, more than 7,000 drained wallets. The bait is a job offer, the trap a coding test.
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
July 2, 2026 8:59 PM

Binance Is Out of the EU: How to Move to a MiCA-Regulated Exchange
Binance has left the EU market. Which exchanges hold a MiCA licence, how to verify an authorisation is real, and how to move your holdings across step by step.
September 30, 2026 4:15 PM

Zcash today: 2,746 ZEC from the Bitget hack vanish into the Ironwood pool
Wallets from the Bitget break-in pushed 2,746 ZEC into Zcash's Ironwood pool on Wednesday morning, roughly $3.9 million. What the shielding means for tracing, and what applies to your exchange account from July 2027.
September 10, 2026 9:13 AM

Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
Trezor users received a fake STM32 entropy warning sent from a real Trezor address. Here is what happened and what to do if you clicked.
August 5, 2026 10:33 PM

$130 Million Gone Because the Randomness Was Predictable: Which Hardware Wallet You Can Still Buy
The Coldcard flaw proved the most respected wallet is not the safest. Which vendor has which track record – and why now is the wrong moment to pause your savings plan.
December 21, 2019 10:53 AM

Upbit Cryptocurrency Exchange Hack – The Story So Far
In one of the biggest heists in the cryptocurrency arena, the Korean exchange Upbit was compromised on 27-Nov-2019 during which a rogue entity managed to transfer 342,000 ETH (estimated to be worth approximately 52 million US dollars or 58 billion […]
August 23, 2018 5:37 PM

North Korea Hacks Crypto Exchange With First-Ever macOS Malware
Hackers from North Korea were able to hack into a cryptocurrency exchange with a malware that was developed to target both Windows and macOS systems.
August 6, 2026 3:05 PM

MiCA Register 2026: Only 21 of 329 Licences Are Real Exchanges
ESMA publishes the register of MiCA-authorised providers as an open file. We worked through all of it — and the result is not what the phrase “licensed crypto exchange” suggests.
May 15, 2024 12:04 PM

Crypto Scams: How to Protect Your Cryptos?
With the rise of crypto scams, and while international efforts are still working to combat these threats and protect investors, some recent tactics have been identified, and here is your full guide.
June 18, 2025 12:05 PM

BREAKING: Israeli-Linked Hackers Allegedly Wipe Out Nobitex Exchange
Nobitex, Iran’s top crypto exchange, has reportedly lost $48.65 million in a massive hack. Linked to Israeli cyber group Predatory Sparrow, the attack allegedly wiped out 95% of the platform’s assets.
August 11, 2026 9:18 AM

Your Crypto Exchange Is Telling You to Withdraw: How to Spot Phishing After the MiCA Deadline
Unauthorised crypto providers now have to tell their EU customers to withdraw, which leaves fraudsters an easy run with faked requests. Here is how to check in two minutes whether the message is genuine.
December 26, 2024 1:08 PM

BGB News: Bitget Token Reaches New ATH Amid Market Momentum
Bitget Token (BGB) defies the market downtrend, hitting a new ATH of $7.32. What's driving this 368% surge and what the future holds for this top-performing cryptocurrency?
May 4, 2019 5:44 PM

Microsoft Hackers Stole Crypto Using Victims Emails
Another batch of crypto users have lost money recently through an unlikely breach. Recently, Microsoft services such as Hotmail, MSN, and Outlook have been hit by a breach. It was later learned that the breach was due to an employee’s […]
September 29, 2026 7:12 PM

MEXC Refunds $340,000: The Attacker's API Key Survived the Account Freeze
During an account takeover at MEXC, an attacker created an API key with withdrawal rights that the exchange did not revoke when it restored the account. Twenty-seven minutes after the withdrawal freeze expired, roughly $340,000 was gone.
June 30, 2026 11:20 PM

How to Switch from Binance to a MiCA Regulated Crypto Exchange
Binance is winding down EU services after missing the MiCA deadline. Here's why it's happening and how to move your funds to a regulated platform safely.
September 10, 2026 1:21 AM

Crypto Exchanges Head to Head: Which Pairing Is Cheaper Where
Before opening an account, the question is rarely which exchange is best overall, but whether it should be this one or that one. This article sorts through the most searched head-to-heads, puts the cost per 1,000 euros side by side and explains the most expensive mix-up: one provider with two interfaces and a factor of seventeen between them.
September 8, 2026 7:23 AM

Compensation After an Exchange Hack: What Twelve Crypto Providers Really Promise German Customers
After $322 million in losses in a single September week, the question is who replaces stolen coins. On September 8, 2026 we retrieved the security and legal pages of twelve providers and evaluated what is promised there.
September 3, 2026 10:21 AM

Bitcoin Lost in a Wallet Hack: What Tax Applies in Austria?
Bitcoin lost to hackers? In Austria, the theft of privately held coins generally does not create a capital loss you can use for tax. Only a later payout can change that.
October 1, 2026 4:21 AM

Velocity Replaces Drift After the 285 Million Dollar Hack: What Changes for Investors in Germany
The Solana perp DEX Drift is back as Velocity, and since September 29, 2026 a new team has been running it. What the overhaul after the outflow of 285 million dollars means for your deposits, for settlement in USDT and for the legal position in Germany.
September 29, 2026 10:33 AM

ESMA puts reverse solicitation on its 2027 watch list: what investors need to know about exchanges without an EU licence
ESMA presented its work programme for 2027 on September 28, 2026 and made reverse solicitation a supervisory priority. What that means if your coins sit with a provider without EU authorisation, and which three steps make sense now.
September 20, 2026 4:15 PM

Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email
After every major data breach, the number of phishing emails sent in the name of crypto exchanges and wallet manufacturers rises. This article shows you how to recognise such a message, which data a reputable provider never requests by email, and what to do in the first hour after a click.
September 1, 2026 7:27 AM

Clipboard Attack: How Malware Swaps the Wallet Address You Copied
A clipper replaces the receiving address between copying and pasting with the attacker’s, and your wallet’s checksum notices nothing. What Microsoft and the Federal Office for Cybersecurity have documented, and which check really makes the attack come to nothing.
More from CryptoTicker
