Déjà Vu, Lazarus Crew: $387.5m Bitget Exploit Repeats a Pattern
This article originally appeared in Galaxy Research's weekly newsletter. Subscribe to get timely insights delivered to your inbox every Friday morning.
Late last week, Bitget disclosed that attackers had stolen $387.5 million from its hot and warm wallets through a series of unauthorized transfers, and it temporarily halted all withdrawals.
There's a specific feeling you get reading a crypto hack post-mortem and realizing you've already read it. Not just a similar one, the same one, with the nouns swapped.
First, let’s recap what happened with Bitget. The losses span 11 blockchains, including Ethereum, XRP, TRON, Arbitrum, Base and BSC, and the largest single-chain loss was about $83 million in XRP. According to Bitget CEO Gracy Chen, private keys and cold wallets were not compromised, and her statement is confirmed by hundreds of millions of dollars in tokens remaining in the exploited addresses (more on this distinction in OUR TAKE below). Instead, attackers exploited two third-party security products (utilizing a zero-day exploit to obtain high-level internal credentials), inserted fraudulent withdrawal commands into the wallet backend, and deleted those commands after the funds were sent out. SlowMist, a security firm hired by Bitget, traced the earliest malicious activity to Aug. 31 and recovered a custom withdrawal tool built around Bitget's withdrawal logic. It all points to a highly researched, targeted exploit of Bitget’s wallet management. Bitget attributes the attack to North Korean actors, citing IP behavior and onchain analysis, and onchain sleuthing firms Elliptic and TRM found wallet overlaps with prior hacks.
Much of the stolen funds moved through THORChain, which declined Chen's request to refuse service on the grounds that it is decentralized and permissionless (just ignore the security freezes it has done in the past). NEAR Intents took the opposite approach, blocking more than $50 million in attempted laundering flows and freezing about $503,000 mid-execution. Bitget's protection fund, and applicable Proof of Reserve (PoR) overcollateralization, covered the exploit amount, with Bitget covering the entirety of the exploit from the protection fund, which has since been topped up to $300m.
Then on Thursday, NEAR Intents got hit with an exploit. A bug in its Omni deposit and withdrawal infrastructure led to roughly $3.8 million in losses, which it says it will fully compensate. ZachXBT flagged multiple abnormal outflows from the BSC hot wallet, with the funds sent to KuCoin and bridged onward to Bitcoin.
Our take
If this episode sounds familiar, it should. In February 2025, the North Korean hacker group Lazarus took $1.5 billion from Bybit the same way. Instead of stealing Bybit's keys, they compromised Safe{Wallet}'s infrastructure, served the signers a doctored interface, and the signers approved what looked like a routine transfer. The cryptography worked perfectly. It signed exactly what it was told to sign.
Nobody attacks the private-key math. They attack whoever, or whatever, tells the math what to do.
That's the landscape for major exploits these days. Nobody attacks the private-key math, because that math is (for now) unbreakable. They attack whoever, or whatever, tells the math what to do.
A private key is a perfect (depending on the cryptographic protocol’s quantum resistance) mathematical way to protect your funds. It will sign anything anyone puts in front of it, so protecting it is utmost. Exchanges’ private key security is some of the best in the world, and we haven’t seen a private key exploit from a major crypto venue in years. Phemex had a private key exploit in January 2025 for only ~$50m, and Coincheck had a major $500m+ exploit in 2018, but that might as well be the Paleozoic era in crypto years. Private key security is mostly solved, so for exploiters the valuable target isn't the key; it's whoever or whatever decides what gets put in front of the key.
We don't know the full details yet, but the shape of the theft tells you most of what you need. If you had the keys, you'd take everything. Instead, Bitget's first notice described unauthorized transfers from a limited number of hot wallets, and SlowMist believes the haul would have been larger if two forged BTC withdrawal orders hadn't errored out. That's what impersonating an approval pipeline looks like: you only get what the pipeline will process, one convincing request at a time. A partial drain is the fingerprint of an exploit in an intermediary service, not a key exploit.
Bitget still hasn't named the vendors that were exploited. The forensic reports call them "Product A" and "Product B." Hopefully it isn't Gnosis Safe again. SlowMist described multiple “nodes” of Product A being infected with malicious code from the zero-day exploit.
Nick Szabo wrote "Trusted Third Parties Are Security Holes" in 2001. Every year, the industry rediscovers this lesson, each time at a cost of roughly nine figures. The cryptographic math is secure; it’s the structure around it that needs hardening. The AI industry learned a similar lesson this summer when frontier labs’ misaligned agents exploited third-party integrations to escape testing sandboxes.
The aftermath has its own déjà vu. The bulk of the stolen funds was moved and converted, some through THORChain, and THORChain’s X handle replied that it is decentralized and permissionless, so its hands were tied. The Bybit loot (as well as portions of ColdCard and countless other exploits) followed a similar chain-hopping path through THORChain, so at this point it's less a bridge than a getaway car for the DPRK.
One more thing. Nobody has attributed Thursday's exploit of NEAR Intents, and we want to be clear that we are not attributing it either. We simply observe that on Monday NEAR Intents confiscated $500,000 of what looks like Kim Jong Un’s lunch money, and on Thursday someone pilfered $3.8 million from the multichain transaction protocol’s BSC hot wallet. Through the deposit and withdrawal infrastructure. Which is, if you've been following along, the intermediary layer.
Déjà vu. Again.
Legal Disclosure:
This document, and the information contained herein, has been provided to you by Galaxy Digital Inc. and its affiliates (“Galaxy Digital”) solely for informational purposes. This document may not be reproduced or redistributed in whole or in part, in any format, without the express written approval of Galaxy Digital. Neither the information, nor any opinion contained in this document, constitutes an offer to buy or sell, or a solicitation of an offer to buy or sell, any advisory services, securities, futures, options or other financial instruments or to participate in any advisory services or trading strategy. Nothing contained in this document constitutes investment, legal or tax advice or is an endorsement of any of the stablecoins mentioned herein. You should make your own investigations and evaluations of the information herein. Any decisions based on information contained in this document are the sole responsibility of the reader. Readers should consult with their own advisors and rely on their independent judgement when making financial or investment decisions.
Participants, along with Galaxy Digital, may hold financial interests in certain assets referenced in this content. Galaxy Digital regularly engages in buying and selling financial instruments, including through hedging transactions, for its own proprietary accounts and on behalf of its counterparties. Galaxy Digital also provides services to vehicles that invest in various asset classes. If the value of such assets increases, those vehicles may benefit, and Galaxy Digital’s service fees may increase accordingly. The information and analysis in this communication are based on technical, fundamental, and market considerations and do not represent a formal valuation. For more information, please refer to Galaxy’s public filings and statements. Certain asset classes discussed, including digital assets, may be volatile and involve risk, and actual market outcomes may differ materially from perspectives expressed here.
For additional risks related to digital assets, please refer to the risk factors contained in filings Galaxy Digital Inc. makes with the Securities and Exchange Commission (the “SEC”) from time to time, including in its Quarterly Report on Form 10-Q for the quarter ended September 30, 2025, filed with the SEC on November 10, 2025, available at www.sec.gov.
Certain statements in this document reflect Galaxy Digital’s views, estimates, opinions or predictions (which may be based on proprietary models and assumptions, including, in particular, Galaxy Digital’s views on the current and future market for certain digital assets), and there is no guarantee that these views, estimates, opinions or predictions are currently accurate or that they will be ultimately realized. To the extent these assumptions or models are not correct or circumstances change, the actual performance may vary substantially from, and be less than, the estimates included herein. None of Galaxy Digital nor any of its affiliates, shareholders, partners, members, directors, officers, management, employees or representatives makes any representation or warranty, express or implied, as to the accuracy or completeness of any of the information or any other information (whether communicated in written or oral form) transmitted or made available to you. Each of the aforementioned parties expressly disclaims any and all liability relating to or resulting from the use of this information. Certain information contained herein (including financial information) has been obtained from published and non-published sources. Such information has not been independently verified by Galaxy Digital and, Galaxy Digital, does not assume responsibility for the accuracy of such information. Affiliates of Galaxy Digital may have owned, hedged and sold or may own, hedge and sell investments in some of the digital assets, protocols, equities, or other financial instruments discussed in this document. Affiliates of Galaxy Digital may also lend to some of the protocols discussed in this document, the underlying collateral of which could be the native token subject to liquidation in the event of a margin call or closeout. The economic result of closing out the protocol loan could directly conflict with other Galaxy affiliates that hold investments in, and support, such token. Except where otherwise indicated, the information in this document is based on matters as they exist as of the date of preparation and not as of any future date, and will not be updated or otherwise revised to reflect information that subsequently becomes available, or circumstances existing or changes occurring after the date hereof. This document provides links to other Websites that we think might be of interest to you. Please note that when you click on one of these links, you may be moving to a provider’s website that is not associated with Galaxy Digital. These linked sites and their providers are not controlled by us, and we are not responsible for the contents or the proper operation of any linked site. The inclusion of any link does not imply our endorsement or our adoption of the statements therein. We encourage you to read the terms of use and privacy statements of these linked sites as their policies may differ from ours. The foregoing does not constitute a “research report” as defined by FINRA Rule 2241 or a “debt research report” as defined by FINRA Rule 2242 and was not prepared by Galaxy Digital Partners LLC. Similarly, the foregoing does not constitute a “research report” as defined by CFTC Regulation 23.605(a)(9) and was not prepared by Galaxy Derivatives LLC. For all inquiries, please email [email protected].
©Copyright Galaxy Digital Inc. 2026. All rights reserved.