@QuanMed_AI- medical robotics research system by AI and Quantum not big Pharma on @Quan_Chain the only auto-migrating quantum chain. MSc Neuro/AI-Robotics Dev
Nobody stole the keys. That's what makes this one different.
Bitget lost $387.5 million on Thursday making it the largest crypto theft of 2026. Attackers got into a backend system in its wallet infrastructure & fed it forged transaction data.
Bitget's own authorization process then approved the transfers as routine. Nineteen transfers across five blockchains, including 103 million XRP worth about $157 million.
Private keys were never compromised. Cold wallets were never touched. Every security control people usually argue about held & the money left anyway, because the system was persuaded rather than broken.
Attribution points at North Korea. CEO Gracy Chen says IP addresses match VPNs used by a DPRK-linked group & the on-chain behaviour matches past operations. Elliptic calls it highly likely & notes the stolen funds touched addresses previously used to launder last year's $1.4 billion Bybit theft.
Bitget says its User Protection Fund covers the whole loss. Worth knowing what that fund is: roughly 5,500 bitcoin. So the insurance is denominated in the same asset class it's insuring & its dollar value moves with the market it's meant to protect users from.
Withdrawals are paused. Deposits & trading stayed open. There's a bounty paying 5% for freezing attacker funds, 5% for recovery & some blockchain foundations have already frozen addresses.
Custody debates usually stop at hot wallet versus cold wallet. This one says the vault was fine. The paperwork wasn't.