With the Bitget breach added to the year's ledger, cryptocurrency theft linked to North Korean state actors has passed $1 billion for 2026, according to blockchain analytics firm Elliptic — with nearly four months of the year still to run.

Elliptic counts the Bitget loss at $357 million by its own methodology — Bitget itself reported $351.6 million affected — and assesses the theft as likely carried out by North Korea-linked hackers, Bloomberg reported. That assessment is shared in structure, if not yet in certainty, by TRM Labs, whose analysis found the laundering infrastructure used by the Bitget attacker overlaps with wallets that processed the Bybit and AFX Bridge thefts — a network TRM says it has never observed working with any other group.

The Year So Far

Before Bitget, hacks attributed to North Korea accounted for roughly $690 million in 2026, according to TRM's dataset. The bulk came from just two operations: the Drift Protocol theft, valued around $285 million, and the KelpDAO exploit. If the Bitget theft is formally attributed, TRM says 2026 would become the second-largest year on record for North Korean crypto theft in its data, behind only 2025 — the year of the $1.5 billion Bybit cold-wallet theft, which the FBI attributed to the TraderTraitor cluster associated with Lazarus Group.

The longer arc is steeper still. Chainalysis counted $1.34 billion stolen by North Korean groups across 47 incidents in 2024, and Elliptic estimated in early 2025 that the total since 2017 had passed $6 billion, with proceeds reportedly directed toward the country's ballistic missile program, per BBC reporting cited at the time.

Attribution Discipline Still Applies

None of the year's headline numbers are final. The Bitget attribution rests on IP patterns, laundering-network overlaps and tradecraft similarities — strong circumstantial evidence, but not the definitive technical attribution TRM says it expects to emerge in the coming days. Bitget's CEO has called North Korean involvement "very likely"; investigators have not used stronger language. By precedent, formal attribution — where it comes — arrives via an FBI advisory or equivalent government statement, as it did weeks after Bybit.

The pattern across the year's incidents is nonetheless consistent enough to act on. The dominant attack class is not broken cryptography but manipulated authorization: backend compromises and spoofed transaction displays that induce legitimate systems and signers to approve transfers, at Bybit in 2025 and at Bitget now. For exchanges, the defensive priorities that follow are unglamorous and known — integrity checks on what authorizers actually see, isolation of backend wallet systems, and pre-arranged freeze coordination with issuers and bridges for the first hours of an incident.

For everyone else, the $1 billion figure is a reminder of who the counterparty increasingly is: a state program that treats exchange infrastructure as a funding channel, and has now cleared ten figures in a single year three times in the past three years.

TrustGrade tracks exchange security posture and verified incident data. trustgrade.ai.