North Korea named as primary suspect in $387 million Bitget crypto hack
- ID
- 29257
- Status
- summarized
- Published
- 28 Sep 2026, 8:00 PM
- Fetched
- 28 Sep 2026, 8:32 PM
- Provider
- Tom's Hardware
- Category
- technology
- Original URL
- https://www.tomshardware.com/tech-industry/cryptocurrency/north-korea-named-as-primary-suspect-in-usd387-million-bitget-crypto-hack-investigators-identify-ip-addresses-tied-to-vpn-infrastructure-previously-used-by-north-korean-hacker-groups-thieves-swapped-stablecoins-for-eth-in-minutes-to-dodge-freezes
- Source URL
- https://www.tomshardware.com/feeds/all
Summary
- Score
- 3.0
- Created
- 28 Sep 2026, 8:33 PM
- Tags
- Audience
- foundersdevelopers
What happened
Bitget is reported to have lost $387 million in a crypto hack, with investigators naming North Korea as the primary suspect based on IP addresses tied to VPN infrastructure previously used by North Korean hacker groups. The stolen funds were stablecoins that the thieves swapped into ETH within minutes, apparently to outrun issuer freeze mechanisms. Note: the supplied article body is only Tom's Hardware site navigation and paywall boilerplate, so no attack vector, timeline, or exchange confirmation is actually in the text.
Why it matters
The one operational detail here is the minutes-long stablecoin-to-ETH swap, which implies issuer freeze and blacklist responses did not land fast enough to matter. If your product or treasury plan treats stablecoin freezing as a recovery mechanism for fraudulent or stolen transfers, that assumption needs re-checking against a minutes-scale window rather than an hours-scale one. Beyond that, this excerpt carries no Malaysian, Southeast Asian, or AI/tooling angle, so there is little for local builders to act on.
Discussion angle
If stablecoins can be swapped to ETH faster than a freeze can be issued, does the 'reversible payments' pitch that stablecoin rails make to Malaysian merchants and SaaS billers still hold up — and what would you build instead as a recovery path?