DPRK-attributed threat actors stole $387 million from Bitget on September 24, 2026, moving the assets through 23 initial transfers across Ethereum, XRP Ledger, Zcash, and Tron. Chainalysis used investigator-directed AI automation to reconcile cross-chain …
« Reports in 2026
593 reports
SafeDep confirmed PolinRider loaders in 35 GitHub repositories, where frequently executed build and test scripts resolved rotating C2 addresses from Ethereum transactions. Two operator wallets exposed 11 servers, and related infrastructure delivered Node.…
Attackers exploited a zero-day in an unnamed third-party security product, obtained privileged internal access, and moved laterally to Bitget's production wallet job server. A custom withdrawal tool forged risk-control parameters and caused the exchange's…
SlowMist said its investigation of the Bitget hot-wallet theft found prior compromise activity involving two third-party security products and a wallet application host. The investigation recovered a customized withdrawal tool that forged risk-control par…
AhnLab documented six spear-phishing patterns targeting organizations in South Korea during August 2026, with LNK files accounting for the largest share of detected attacks. The chains used PowerShell, AutoIt, scheduled tasks, GitHub-hosted payloads, PubN…
AhnLab observed multiple LNK- and HWP-based spear-phishing chains targeting organizations in South Korea during August 2026. The chains used PowerShell, AutoIt, scheduled tasks, GitHub-hosted payloads, PubNub communications, DLL side-loading, Python backd…
Security Alliance handled two DPRK-related cases during the week, involving a fake Microsoft Teams link and a Telegram account-takeover report, with no reported financial losses. The organization published 11 newly identified domains associated with the D…
ZachXBT reported that Chinese illicit actors were seeking operational support in public Discord and Telegram channels while laundering funds from the $387 million Bitget exploit for alleged DPRK attackers. The funds were reportedly chain-hopped through br…
An investigation into a compromised Web3 and fintech GitHub repository found a malicious VS Code workspace task that invoked Node.js on an embedded WOFF2 file carrying an obfuscated JavaScript loader. The loader used an Ethereum wallet as a dead-drop reso…
PolinRider, a DPRK-linked cluster associated with Contagious Interview activity, is testing multiple infection variants across compromised GitHub repositories rather than replacing each build in a linear sequence. An eight-month Binary-Mindz infection inv…
Attackers stole an estimated USD 351.6 million from Bitget’s hot and warm wallets after allegedly compromising a backend system and manipulating transaction data presented to the exchange’s authorization process. The proceeds were divided among fresh wall…
The DPRK-attributed XCTDH campaign added HashHiding, also known as NullReceiver, as an always-on Ethereum channel for recovering its current command-and-control address. Malware decodes an IPv4 address and port from fabricated Ethereum transaction destina…
Elliptic assesses the theft of more than $350 million from Bitget as highly likely to be DPRK-linked, pushing its tracked total of North Korean cryptocurrency theft in 2026 above $1 billion. Attackers reportedly compromised a backend wallet-infrastructure…
Bitget said attackers transferred approximately $387.5 million in assets across Ethereum and other EVM networks, XRP Ledger, Zcash, and TRON after bypassing its security controls. The exchange identified four primary attacker-controlled receiving addresse…
Bitget reported losses across several assets and networks during a September 24 hot-wallet security incident, while confirming that its cold wallets and separately operated Bitget Wallet remained unaffected. Based on IP behavior and on-chain analysis, the…