Suspected DPRK-Linked Theft Passes $1 Billion for 2026

The Bitget breach has pushed the annual haul attributed to suspected North Korean-linked actors past $1 billion for 2026, Insurance Journal reported. The attribution remains in the "consistent with techniques used by DPRK-linked hacker groups" category — Bitget CEO Gracy Chen's own phrasing — and has not been confirmed by forensic findings; SlowMist and Mandiant both describe their work as interim. The exchange says the loss is covered by its $464 million user protection fund. The $1 billion figure counts thefts where DPRK involvement is suspected, not proven — a distinction that matters when the same tally informs policy debates.

Bitget Customers Pull $463 Million Since the Hack

Bitget has seen roughly $463 million in customer outflows since the September 24 breach, Claims Journal reported, even as the exchange restored withdrawals for its three major assets — BTC, ETH and USDT — on schedule this week, per crypto.news. Chen said Bitget will replenish the user protection fund with its own capital, targeting a balance above $300 million within one week. The outflow number is the first hard measure of user trust since the incident, and it represents a fraction of the exchange's stated reserves — but the next weeks of withdrawal data will show whether the phased restart holds.

Recovery Odds: "Not Very Optimistic"

Chen, speaking on Cointelegraph's Chain Reaction podcast, said she is "not very optimistic" about fully recovering the roughly $388 million stolen, citing the limited recovery from Bybit's 2025 hack as the realistic ceiling. The laundering trail so far supports the caution: over $50 million in attempted swaps rejected by NEAR Intents, an estimated $79 million in ETH already converted to Bitcoin through THORChain, and the first 2,746 ZEC — about $3.9 million — shielded inside Zcash's Ironwood pool on Wednesday.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.