Cryptocurrency exchange Bitget has begun resuming customer transactions following a hack that resulted in the transfer of roughly $387.5 million (£293m) in funds to addresses controlled by the attackers.
Bitget said the methods used in the attack were “highly consistent” with those of North Korean attackers.
The exchange, the world’s fifth-largest by spot trading volumes according to CoinMarketCap, halted transactions after detecting the attack on 24 September.
Initially Bitget estimated $351.6m had been stolen, which it later raised to $387.5m based on a more complete analysis of the transfers that had taken place.
Bitget said the thefts would be covered by its User Protection Fund.
“Based on IP behaviour patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organisations,” said Bitget chief executive Gracy Chen.
The company began resuming Bitcoin, Ethereum and Tether transactions on 28 September, with remaining services including fiat services and peer-to-peer trading planned to resume by 2 October.
The hack is the largest of a crypto firm so far this year, according to TRM Labs, which has recorded 333 other incidents in 2026 totalling $1.73bn.
Largest crypto heist this year
In February of last year, North Korean attackers stole $1.5bn from exchange Bybit in the largest single crypto theft to date.
North Korean hackers stole an estimated $2bn of cryptocurrency in 2025, which authorities have said is being used to fund weapons programmes.
As the value of cryptocurrency has risen, large crypto holders have become prime targets for thieves, with some being made the subject of physical attacks.
Hackers who stole customer data from fintech Revolut last month targeted information on large crypto holders, then demanded a ransom from the company to refrain from selling it to other criminals.