
DeFi3 min read
AI Agent Payments Expand Across XRP Ledger
XRPL tracked payments reportedly rose from one million to 7.09 million between July and September, showing faster machine activity. The XRPL AI Hub reportedly lists 160 merchants and 2,276 li
The exchange first detected unauthorized transfers at 18:31 UTC on Sept. 24. In its official security update, Bitget said subsequent onchain tracing found additional affected assets on Zcash
The exchange first detected unauthorized transfers at 18:31 UTC on Sept. 24. In its official security update, Bitget said subsequent onchain tracing found additional affected assets on Zcash and Tron, lifting the confirmed amount by about $35.9 million. Bitget stressed that the higher number reflects a more complete accounting of the original breach, not a second attack.
That revision makes the incident the largest publicly reported crypto theft of 2026 so far.
How the Bitget Hack UnfoldedSept. 24, 18:31 UTC — Unauthorized transfers detected. Bitget says its monitoring systems spotted abnormal transfers involving portions of its hot and warm wallet infrastructure. The exchange initially estimated the loss at $351.6 million and suspended withdrawals while leaving deposits and trading operational. Cold wallets were not affected, according to the company.
Hours later — Withdrawal freeze begins. Users could continue trading, but assets could not be withdrawn while Bitget reviewed its wallet infrastructure. The exchange said its more than $464 million User Protection Fund was sufficient to cover the initial loss.
Coinpaper’s first look at the breach focused on the emerging question of whether North Korean hackers were responsible.
Sept. 25 — Attack method becomes clearer. CEO Gracy Chen said attackers apparently compromised a backend wallet system and manipulated transaction data so unauthorized transfers could pass through Bitget’s approval process. The company says private keys themselves were not stolen.
Sept. 25 — Loss estimate rises to $387.5 million. Bitget added assets previously missed in its initial classification, including funds moved through Zcash and Tron. Affected assets included XRP, ETH, USDT, USDC, ZEC, BNB, AVAX and TRX across several networks.
Why North Korea Is SuspectedBitget has not established the attacker’s identity conclusively.
However, blockchain intelligence firm Elliptic says the breach is highly likely to be DPRK-linked, citing infrastructure overlap with previous North Korea-attributed activity and similarities in the attack pattern. Elliptic estimates the incident pushed suspected North Korean crypto thefts above $1 billion in 2026.
That would continue a pattern already visible after the North Korea-linked Bybit hack, where attackers used thousands of addresses and cross-chain movements to complicate asset recovery.
The Withdrawal Freeze Is Now the Bigger User QuestionFor customers, the most immediate issue is no longer how much was stolen but when withdrawals return.
Bitget says the vulnerability has been identified and remediated, no further unauthorized transfers are possible, and Mandiant and SlowMist are assisting with the investigation. It has also launched a recovery bounty offering 5% of successfully frozen or recovered funds to eligible contributors.
The exchange says user balances remain intact and the Protection Fund can absorb the loss.
That claim will now be tested operationally. The next milestone is not another hack estimate, it is whether Bitget can reopen withdrawals smoothly without triggering a liquidity crunch or renewed security concerns.
The comparison with Bybit is instructive. After its much larger 2025 breach, Bybit kept withdrawals running and later rebuilt its reserves, while Coinpaper tracked how the $1.4 billion theft reshaped exchange security.