At 18:31 UTC on Thursday 24 September, Bitget's monitoring systems flagged unauthorised transfers leaving one of its hot wallets. The exchange suspended withdrawals within the hour. Its first public figure was US$351.6 million. By the following day, after finding Zcash and TRON balances that the initial count had missed, the number had been revised to about US$387.5 million.

Blockchain analytics firm Elliptic says the theft is highly likely the work of North Korea, and that it pushes suspected North Korean crypto theft past US$1 billion for 2026.

That is the story everyone is running. The part worth your attention, if you are reading this from Indonesia, sits further down.

What happened

Bitget lost 387.5 million dollars against a stated user protection fund of 464 million dollars
Bitget's own figures for the loss and the funds it says cover it.

One hot wallet was drained. Bitget says its cold wallets were untouched, customer balances are accurate, and deposits and trading continued while withdrawals were paused as a precaution.

Chief executive Gracy Chen said the security team activated emergency response protocols immediately, flagged the receiving addresses and contacted law enforcement. The company points to a User Protection Fund it puts at more than US$464 million, larger than the loss, and proprietary assets it states at more than US$1 billion.

The largest single asset taken was XRP, alongside ether, BNB, USDT, USDC and others.

Who is being blamed, and on what basis

Attribution in these cases is probabilistic, and it is worth being precise about what has and has not been established.

Bitget's own evidence. Chen said the attackers used IP addresses matching the VPN patterns of a known North Korean group, and that the operation resembled previous ones.

Elliptic's on-chain analysis. The firm traced connections between stolen XRP and ether and funds from earlier thefts already attributed to North Korea, including address overlap with the Bybit breach.

Independent researchers. Taylor Monahan of MetaMask and the pseudonymous investigator ZachXBT linked the funds to Lazarus, the Western label for North Korea's state-backed hacking operations.

Three independent methods pointing the same way is strong. It is still an assessment, not a court finding, and no government had published a formal attribution at the time of writing.

The bigger number

The Bitget breach accounts for about 39 per cent of suspected North Korean crypto theft in 2026
Suspected North Korean crypto theft in 2026, and Bitget's share of it.

This single night accounts for roughly 39 per cent of what Elliptic attributes to North Korea for the whole of 2026.

For scale, the Bybit breach attributed to the same group took US$1.4 billion in February 2025. TRM Labs reported in April 2026 that cumulative North Korean crypto theft had passed US$6 billion since 2017, and that North Korean actors were behind 76 per cent of all stolen crypto value through that month.

Treat the 2026 figure as a floor. It counts suspected incidents that analysts have been able to trace.

The honest counterweight

Two things should be said in Bitget's favour, and one against the easy conclusion.

The operational response was reasonable. Detection, withdrawal suspension, address flagging and law enforcement contact all happened within hours. Cold storage held. A protection fund that exceeds the loss is a real buffer, whatever else is true.

Being hacked is not evidence of negligence. Bybit was the largest exchange breach in history and Bybit was not a fly-by-night operation. Hot wallets are a structural attack surface for every exchange that lets customers withdraw quickly.

But a company-funded backstop is not the same as a regulated one. The User Protection Fund exists because Bitget says it does, in the amount Bitget states. No supervisor verifies it, no law compels its use, and no authority adjudicates a dispute over it.

That distinction is the whole point of the next section.

The part that matters in Indonesia

OJK publishes a whitelist of every operator licensed to trade digital financial assets in Indonesia. As of its most recent published list, that is 26 licensed digital asset traders and three registered candidates: names like Indodax, Pintu, Tokocrypto, Reku, Pluang, Bittime, Ajaib and Upbit Indonesia.

Bitget is not on it.

That is a statement about Indonesian licensing, not about Bitget's security. But it has consequences that most Indonesian users of offshore exchanges have never thought through.

There is no OJK recourse. If an unlicensed offshore platform declines to make you whole, you cannot escalate to OJK, and the LAPS-SJK dispute resolution system does not cover it. Your remedy is whatever the company's terms of service say, adjudicated wherever the company is incorporated.

The criminal exposure sits with operators, not users. Operating without a licence is an offence under Law 4 of 2023. Indonesian retail users are not the target of that provision. What they lose is protection, not liberty.

Licensed does not mean unhackable. A local licensed exchange can lose a hot wallet exactly the way Bitget did. The difference is not that the theft cannot happen. It is that afterwards there is a supervisor, a settlement window and a complaints process with legal force behind it.

That is the trade Indonesian users make when they open an offshore account for the deeper liquidity or the longer token list. It is a defensible trade. It is not a free one, and most people making it have not priced it.

What to actually check

Three questions, and they take about ten minutes.

Is the platform on OJK's whitelist? The list is published and updated. If the app is not on it, you are outside the Indonesian consumer protection framework, whatever the app says in its marketing.

What proportion of assets sits in hot wallets? Every exchange keeps some. Reputable ones publish the split or will answer if asked.

What exactly is the protection fund? Ask whether it is segregated, whether its size is attested by anyone independent, and what triggers a payout. A number in a blog post is not an answer to any of those.

Web3 Week Asia: where you can ask the custodians directly

Web3 Week Asia takes place on 11-12 November 2026 in Jakarta, Indonesia. It is a two-day blockchain event that gathers OJK, the exchanges licensed under POJK 27/2024, custody providers and the funds that allocate through them.

The 2025 edition drew more than 5,000 participants, over 100 speakers and more than 200 companies.

Questions about hot wallet ratios and protection funds are answered badly by support tickets and well by a person standing in front of you who has to give a number. That is the practical case for an Indonesia crypto event where the people running this infrastructure are in the room.

Frequently asked questions

How much was stolen from Bitget?

About US$387.5 million. The initial figure was US$351.6 million, revised upward after Zcash and TRON balances were found to have been missed in the first count. One hot wallet was affected on 24 September 2026; Bitget says cold wallets were untouched.

Was North Korea responsible for the Bitget hack?

It is suspected, not proven. Elliptic assessed it as highly likely North Korea based on on-chain links to earlier attributed thefts. Bitget cited matching VPN patterns, and independent researchers reached the same conclusion. No government had issued a formal attribution at the time of writing.

Is Bitget licensed in Indonesia?

No. Bitget does not appear on OJK's published whitelist of licensed digital asset traders. Indonesian users of unlicensed offshore platforms have no OJK recourse if something goes wrong.

When and where is Web3 Week Asia 2026?

Web3 Week Asia takes place on 11-12 November 2026 in Jakarta, Indonesia. It is a two-day crypto and blockchain event covering markets, regulation, infrastructure and venture investment across Southeast Asia.

Sources

OJK's whitelist of licensed and registered digital asset trading operators in Indonesia: https://ojk.go.id/id/berita-dan-kegiatan/siaran-pers/Pages/OJK-Terbitkan-Whitelist-Penyelenggara-Perdagangan-Aset-Keuangan-Digital-Dan-Aset-Kripto-Berizin.aspx

How Indonesia's crypto rulebook came to exist while the US failed to pass one, our earlier analysis: https://www.w3w.asia/articles/clarity-act-failed-senate-vote-crypto-market-asia

Hack timing, the hot wallet breach and Bitget's operational response are from Cybernews and Hackread of 25 September 2026. The revised US$387.5 million figure, Elliptic's assessment and the researcher attributions are from Gizmodo. The US$1 billion 2026 total is Elliptic's. Cumulative North Korean theft figures are from TRM Labs as reported in April 2026. The whitelist composition is from OJK and Coinvestasi. The framing question was raised by Bloomberg on 25 September 2026.

Methodology: every headline figure here is reported by at least two independent outlets, except the composition of Bitget's protection fund, which comes from the company and is labelled as such in the text and on the chart. The attribution to North Korea is described as suspected throughout, because it rests on analytics assessments rather than a formal government or court finding. Bitget's absence from the OJK whitelist was checked against the regulator's own published list and is a statement about licensing status only.

This article is for information only and is not investment advice.