$387M Bitget Hack Traced to North Korea, Pushing Kim's 2026 Crypto Haul Past $1B

North Korea-linked hackers have already stolen more than $1 billion in crypto in 2026, and the year is barely underway.

Blockchain analytics firm Chainalysis has formally tied the $387 million Bitget hack to North Korean state-sponsored actors, confirming what many in the industry feared. The attribution pushes Pyongyang's running total for 2026 above the ten-figure mark, a pace that would shatter the records set in prior years and signal that these operations are becoming faster, more sophisticated, and harder to stop.

The onchain trail is already going cold in real time.

According to Chainalysis, stolen XRP from the Bitget breach is actively being routed through THORChain, the decentralized cross-chain liquidity protocol that has become the preferred laundering highway for state-level crypto thieves. This is not the first time THORChain has appeared in a North Korea attribution. Investigators flagged the same pattern after the $1.4 billion Bybit hack earlier this year, where hundreds of millions in Ethereum were swapped and dispersed across chains within hours.

THORChain operates without KYC, without a central point of control, and without a kill switch. That is its design. It is also exactly what makes it a near-perfect tool for anyone trying to break the onchain link between a stolen asset and a final destination wallet. By the time compliance teams and law enforcement map the swap routes, the funds have often already been converted into Bitcoin and fragmented across thousands of addresses.

Why This Matters Beyond Bitget

The $1 billion threshold is not just a headline number. It represents a strategic shift. North Korea is no longer treating crypto theft as opportunistic. These are coordinated, state-funded operations with dedicated teams, social engineering pipelines targeting exchange employees, and a laundering apparatus that activates within minutes of a successful breach.

For retail holders and institutions alike, the implications are direct. Centralized exchanges remain the primary attack surface. If you are holding significant assets on any CEX, particularly mid-tier platforms with thinner security budgets than Binance or Coinbase, the risk calculus has changed.

What To Watch

THORChain volume spikes in the coming days will be the clearest onchain signal that laundering is still active. Watch for unusual XRP-to-BTC or XRP-to-ETH swap volumes on decentralized trackers like DefiLlama.

Regulators in the US, EU, and South Korea are almost certain to use this attribution as fresh ammunition for tighter CEX withdrawal monitoring and potential pressure on THORChain's node operators.

Move assets you are not actively trading to self-custody. The $1 billion number is not a ceiling. It is a baseline.