What Happened
An attacker compromised a critical backend system inside crypto exchange Bitget’s wallet infrastructure on September 24 and used it to authorize fraudulent transfers out of the exchange’s hot wallets. The theft moved roughly $351.6 million in Ethereum, XRP, BNB, AVAX, USDT, and USDC across several blockchains before Bitget’s security systems flagged the unauthorized activity, with XRP accounting for the largest single-chain loss. Cold storage and private keys stayed untouched, and the exchange’s separate self-custodial wallet product was unaffected.
Bitget CEO Gracy Chen said IP behavior patterns and on-chain analysis point toward tactics consistent with known North Korean hacking operations, without naming a specific group. Several blockchain foundations froze wallet addresses tied to the attacker, and Mandiant and blockchain security firm SlowMist opened investigations. Read the full report from SecurityWeek.
Why This Matters for Canadian Organizations
North Korean state-linked groups have stolen billions of dollars from crypto platforms over the past several years, funding weapons programs under United Nations sanctions the regime otherwise circumvents. The Canadian Centre for Cyber Security’s threat assessments name North Korea among the persistent state actors targeting financial infrastructure, and Canadian crypto exchanges, custodians, and institutional investors sit inside the same global attack surface Bitget occupied, regardless of size.
Canadian platforms registered as money services businesses face FINTRAC reporting obligations, and OSFI-regulated institutions with crypto exposure carry added scrutiny under Guideline B-13 for third-party and technology risk. A hot-wallet compromise at any major exchange resets the baseline for what counts as adequate segregation between operational and cold storage funds, a standard Canadian regulators and auditors increasingly expect platforms to demonstrate rather than assert.
What to Do
Canadian exchanges and custodians should review how backend systems authorize wallet transfers, confirming no single compromised credential or service account moves funds without a second, independently verified approval step. Firms holding crypto assets on customers’ behalf should audit the segregation between hot and cold storage against current practice rather than a policy written years ago, and confirm incident response plans name specific blockchain analysis and law enforcement contacts in advance of a breach, not during one.
Follow ongoing threat actor coverage in our News section and policy angles in Legislation.






