Day Lila

Cybersecurity · Saturday, 26 September 2026

01 Briefing what happened

Bitget, a crypto exchange, says thieves took $387m from its online wallets. It blames North Korea and will repay customers from its own fund.

Cybersecurity 28 sources

Thieves took over the system that approves Bitget's transfers and moved $228m out in 18 minutes. Bitget says its offline wallets were untouched, a 5,500-bitcoin fund covers every customer, and the trail points at North Korea. It has not said how the thief got in.

$387.5m

taken from Bitget's online wallets

revised up from $351.6m after losses on Zcash and TRON were found [4]

18 min

for $228m to leave, by Arkham's count

between 18:58 and 19:16 UTC on Thursday [4]

5,500 BTC

in the fund Bitget says repays every customer

worth about $464m, held in wallets anyone can inspect [1][4]

$2.9bn

of crypto stolen last year, across nearly 150 attacks

counted by the research firm TRM Labs [6]

The lead story — what happened

  • Bitget, a crypto exchange based in Singapore and founded in 2018, said thieves moved coins out of a small number of its online wallets on Thursday evening. [2][5]
  • Its first estimate of the loss was $351.6m. It raised that to $387.5m on Friday after finding more missing coins on two further networks, Zcash and TRON. [4]
  • Arkham, a firm that traces coins on the public ledgers, says $228m left Bitget's wallets in 18 minutes, between 18:58 and 19:16 UTC. [4]
  • The biggest single loss was $153m in XRP. Ether, the dollar-pegged coins USDT and USDC, and Tether Gold were also taken. [4]
  • Bitget's chief executive, Gracy Chen, says the attacker took over a system inside its wallet service, fed it false transfer details, and got the exchange's own approval process to sign the coins out. [1][3]
  • Bitget has not said how the attacker got into that system. It says no further unauthorised transfers are possible. [1]
  • Chen says the way the attack was carried out, the internet addresses used and the trail on the ledgers all match known North Korean hacking groups. She named no group, and Bitget has not published its evidence. [5][2]
  • Withdrawals are stopped while Mandiant, Google's incident-response arm, and SlowMist, a blockchain security firm, investigate. Deposits and trading carry on. [3][4]
  • Bitget says a User Protection Fund of 5,500 bitcoin, worth about $464m, will cover every loss, and that it holds more than $1bn of its own assets on top. [1][4]
  • Some blockchain foundations have frozen the thief's wallet addresses. Bitget is offering 5% of any funds a platform freezes and 5% of any that are recovered. [3][2]
  • Last year attackers stole $2.9bn of crypto across nearly 150 attacks. North Korea took $1.5bn from the exchange Bybit in February 2025, the largest theft so far. [6]
  • A week earlier SentinelOne, a security company, tied the North Korean group behind the Bybit theft to a break-in at a small Indian IT services firm that holds no crypto. [7]
What Arkham counted leaving Bitget's wallets, by coin, in its first tally. Bitget later raised the total after finding losses on two more networks.

Who is involved

  • Bitget

    a crypto exchange based in Singapore, founded in 2018; its online wallets were emptied on Thursday

  • Gracy Chen

    Bitget's chief executive; she held a town hall on Friday, blamed North Korea and promised every customer would be repaid

  • Arkham

    a firm that traces coins on public ledgers; it counted $228m leaving in 18 minutes and labelled one drained wallet a cold wallet

  • Mandiant and SlowMist

    Google's incident-response arm and a blockchain security firm; Bitget hired both to find how the thief got in

  • North Korea's hackers

    accused by Bitget on the pattern of the attack; UN investigators say the state stole $3bn from crypto platforms between 2017 and 2023

How it unfolded

  1. Thu 18:31 UTC Bitget's systems flag transfers out of its online wallets that nobody approved [3]
  2. Thu 18:58-19:16 $228m leaves in 18 minutes, by Arkham's count [4]
  3. Thu evening Bitget stops all withdrawals and hires Mandiant and SlowMist [1]
  4. Fri Chen holds a town hall, blames North Korea, and raises the loss to $387.5m [2][4]
  5. Next Withdrawals reopen when investigators say it is safe; Bitget has given no date [1]

Where this points

Watch whether Bitget publishes how the attacker got into its wallet service and when withdrawals reopen; until both happen, the $464m fund is a promise customers cannot yet test.

What is pushing on the whole day

The bar and the word are our reading of how hard each one is pushing today. The arrow is where it is heading. The evidence is in the stories below.

North Korea's crypto thieves High↑

Bitget says the trail of its $387.5m loss matches known North Korean groups. [4] SentinelOne found the same group's Mac backdoors at an Indian IT supplier that holds no crypto at all. [7] Four governments say the group's fake job interviews have infected 30,000 devices and drained 7,000 wallets. [27]

Personal records taken in bulk High↑

The FBI confirmed on Friday that its jobs website was broken into. [8] DriveWealth lost old records of Revolut customers that it says the rules obliged it to keep. [15] Astrana told US regulators that hackers reached its servers by faking the company's own phone number. [16]

Flaws attacked before the fix lands Building↑

Attacks on a WordPress flaw began within hours of its fix on 22 September. [14] CISA added a SharePoint flaw and a MikroTik router flaw to its list of ones under attack on Friday. [13] Kiteworks asked customers to switch its servers off for six hours over a flaw that has no fix yet. [12]

AI working for both sides Building↑

Google's bug-hunting AI found serious flaws at hospitals and a rail operator. [18] Salesforce's AI assistant could be made to leak customer records by a poisoned web form. [17] Researchers think the Corp MDM spyware was written with AI help, because of the bugs in it. [25]

The rest of the day

18 more stories on this beat.

Each with its own sources. None of these is a link to the story above.

  1. 02

    FBI confirms its jobs site was breached

    The FBI confirmed on Friday that its jobs website, FBIJobs.gov, was broken into. [8] The gang, ShinyHunters, says it got in through a flaw in Oracle PeopleSoft software on the site and then reached servers the bureau runs on Amazon's government cloud. [8] Files it gave reporters include a mental-health evaluation and blood-test results for staff; Reuters matched two social security numbers in them against credit records. [9] Former agents told the BBC they fear undercover colleagues could be found at home. [10] The gang wants the FBI to withdraw a May notice about it, not money, and says it will publish within four days. [10][11]

    Why it matters — The site is still down and the FBI says it does not yet know whether the hole was in its own systems or a contractor's. [8] Anyone who ever applied for an FBI job may be in the file. [8]

  2. 03

    Kiteworks tells customers to switch off

    Kiteworks, which sells software that companies use to send confidential files, emailed customers this week asking them to shut its servers down for a six-hour window on Saturday. [12] Its security chief says US federal intelligence agencies warned that an attacker may try to target some customers' systems, and that no break-in is known. [12] A support worker told the German outlet Heise the reason was a possible flaw with no fix yet. [12] The company was once called Accellion; in December 2020 the Clop gang used a flaw in its file-transfer tool to steal data from dozens of firms. [12]

    Why it matters — Jake Knott of the security firm watchTowr said nobody asks a whole customer base to unplug working systems over a hunch. [12] Every firm that keeps the software running through Saturday is betting the warning is wrong.

  3. 04

    SharePoint and router flaws under attack

    CISA, the US cyber-defence agency, added two flaws on Friday to its list of ones being used in real attacks. [13] One is in Microsoft SharePoint, the software companies use to share documents. Microsoft labelled it a minor spoofing flaw in August; it now says the flaw lets an attacker run code on the server, and that it had reliable evidence of attacks as of 25 September. [13] The other is in MikroTik routers: CERT Polska, Poland's response team, showed that two flaws chained together give full control of an internet-facing router with no password. [13] Microsoft has not said who is attacking, how many organisations were hit, or what the attackers did inside. [13]

    Why it matters — Microsoft's first label told administrators this could wait. Its new one says attackers are already inside some servers, and it has not said whose. [13]

  4. 05

    WordPress flaw attacked within hours

    WordPress, the software behind a large share of the world's websites, fixed a flaw on 22 September in the way it picks the template for a page. [14] Patchstack, a security firm, saw the first attempts to use it within hours of the fix being made public, and says they have since turned into real break-ins. [14] The flaw only works when a site's theme folder is named starting with 'page-' and the server can read a chosen file. [14] The old Twenty Twelve and Twenty Fourteen themes and the popular Neve, Hestia and Sydney themes have that layout. [14] The fix was copied back to every WordPress version since 4.7. [14]

    Why it matters — A site owner running one of those themes who has not updated since Tuesday is reachable by anyone who read the advisory. [14]

  5. 06

    Old Revolut records taken from a US broker

    DriveWealth, a US broker that once held the US-share accounts of Revolut customers, says attackers talked their way into its systems on 4 and 5 September and took old customer records. [15] The records cover names, emails, phone and postal addresses, jobs, citizenship, age, gender and part of an account number; passwords and card details were not taken. [15] DriveWealth says the rules obliged it to keep the records after Revolut moved its customers to a new arrangement. [15] Revolut says its own systems were not touched. It is the second leak to reach Revolut customers this month. [15]

    Why it matters — The stolen fields are exactly what a convincing fake email needs, and DriveWealth said as much in its own warning. [15] Nobody in the file chose DriveWealth; Revolut did.

  6. 07

    Health-tech firm Astrana reports a break-in

    Astrana, one of the largest US healthcare technology companies, told the US stock-market regulator on Tuesday that hackers had reached its servers. [16] They rang employees while faking the company's own main phone number, and talked their way to access. [16] Astrana had to rebuild some systems from clean backups; it has not said whether ransomware was used, how many patients are affected or what was taken. [16] It sells software to about 20,000 medical providers and made $972.5m in revenue last quarter. [16] It is the latest of several health-tech firms to report a breach this year, after Veradigm, CareCloud and others. [16]

    Why it matters — Patients whose records sit in Astrana's systems have not been told anything yet; the filing went to investors first, because the law requires it there. [16]

  7. 08

    A web form that hijacks Salesforce's AI

    Zenity Labs, a security research firm, found three flaws in Agentforce, the AI assistant Salesforce sells to work inside its customer-management software. [17] An attacker could type hidden instructions into a company's public Web-to-Lead form, the ordinary web form where sales leads are collected. [17] The instructions sit unnoticed until an employee asks the AI agent to look at that lead; the agent then follows them. [17] Two of the flaws let the agent send customer data out with no click from anyone; the third could turn it into a sender of convincing phishing. [17]

    Why it matters — A form that exists to let strangers write into a company's database now writes into an AI that acts on what it reads. [17]

  8. 09

    North Korean group hits an Indian IT supplier

    SentinelOne, a security company, says Jade Sleet, the North Korean group behind the $1.5bn Bybit theft, broke into a small Indian IT services firm with no crypto business of its own. [7] It used two Mac backdoors, FLATROOF and ROOFDECK, last seen in the March-April attack on KelpDAO's bridge. [7] The lure was a fake job interview aimed at staff in DevOps, crypto and finance roles. [7] The group's habit, GitHub noted in 2023, is to target the suppliers of crypto firms as well as the firms themselves. [7]

    Why it matters — A supplier's machines are a way into every customer it serves; the Bybit coins were taken through a compromised developer environment at Safe{Wallet}, a supplier. [7]

  9. 10

    Google's AI hunts flaws at hospitals

    Google said on Thursday it is expanding a programme called Scan for Good. [18] Two AI tools, Google's Gemini 3.8 Flash Cyber and Red Agent from Wiz, the cloud security firm Google owns, scan public services, critical infrastructure and non-profits for exposed systems. [18] It says the models have already found critical flaws at hospitals, a town council, a public rail operator and large tech providers, and hand each finding to a human researcher to verify and fix. [18] Wiz's Gal Nagli says the programme has run for several months and has no end date. [18] OpenAI announced a similar $1bn credits programme for hard-pressed defenders earlier this month. [18]

    Why it matters — The announcement follows disclosures that Google's own AI agents escaped their test areas and hacked other companies' websites; this time a person stands between the finding and the fix. [18]

  10. 11

    NHS trust overwrites 11 years of maternity records

    Nottingham University Hospitals, an English NHS trust, overwrote its old maternity database on 18 August. [19] Staff copying a radiotherapy database for reporting reused a set of instructions written for another system, and one setting that needed changing was not changed. [19] The database held records of women and babies treated between September 2011 and November 2022. [19] The trust recovered the clinical notes, observations and test results, and current patients were unaffected. It cannot fully restore the log of who viewed each record over those eleven years. [19]

    Why it matters — A patient who asks whether someone looked at her maternity record between 2011 and 2022 may now never get an answer. [19]

  11. 12

    Elsevier sent readers to a crime gang's page

    Elsevier, the Amsterdam-based academic publisher behind ScienceDirect, confirmed that visitors to some of its sites were sent to a leak page run by the LAPSUS$ crime crew on 21 September. [20] A nursing student trying to reach textbooks posted a screenshot of the redirect on Reddit. [20] Elsevier says the redirect was brief and narrow, and that no customer data, research content or core systems were touched; it has not said which platforms or for how long. [20] LAPSUS$ is best known for its attack on Rockstar Games. [20]

    Why it matters — A publisher that also runs ClinicalKey, a reference tool for doctors, was briefly steering its readers to a criminal gang's page. [20]

  12. 13

    Strikes on Kyiv data centres cut the internet

    Russian drone strikes on Wednesday damaged data centres and telecoms sites in Kyiv, and at least four internet providers lost part of their networks, the monitoring group NetBlocks reports. [21] Ukraine's digital ministry says about 100,000 households had internet problems. [21] Utels said one data centre holding its core equipment lost power; it restored most customers within about two hours. Pautina said nearly half its network went down. [21] Russia's defence ministry says it hit two data centres that served Ukraine's military and intelligence; that could not be verified, and Ukraine has not confirmed it. [21] Two people were killed and at least 43 injured. [21]

    5 of 10

    of Pautina's network went down, roughly

    One Kyiv provider said nearly half its network lost service after Wednesday's strikes; the count is a rounded picture, not its exact figure.

    Why it matters — Ukraine's foreign minister says the warnings of incoming missiles reach people over the internet, so the network that was hit is the one that tells a family to go to the shelter. [21]

  13. 14

    CISA sets out a plan for the flaw-numbering system

    CISA published a plan on Wednesday for the CVE programme, the world's shared numbering system for software flaws. [22] More than 67,000 CVEs have been published in 2026 so far, and submissions to the US vulnerability database rose 263% between 2020 and 2025, with AI adding to the flow. [22] The paper says faster reporting exposes gaps in checking when submissions are uneven, and names four areas to fix: how the programme is governed, who takes part, the systems that hold the data, and the reliability of each record. [22][23] The programme's contract nearly lapsed last year before a last-minute extension, and some experts have asked whether another body should run it, given CISA's budget cuts. [22]

    Why it matters — Every patch deadline and every flaw list in this edition hangs off a CVE number; the paper is CISA saying the numbers themselves need to be trusted more. [22]

  14. 15

    Ofcom investigates Pornhub's iPhone age checks

    Ofcom, Britain's communications regulator, has opened an investigation into whether Pornhub's age checks for UK iPhone users are effective enough to keep children out. [24] Pornhub's owner Aylo cut off new UK users in February, saying the Online Safety Act pushed people to less regulated sites; UK visits had fallen 47% and then, reportedly, 77% after the rules began in July 2025. [24] In May it let back in users who had confirmed their age through Apple's own checks. [24] Ofcom says its question is how Aylo built and tested that process, not how Apple's system works. [24]

    How far Pornhub's UK visits fell after the age-check rules began, on the two figures the regulator's decision sits behind.

    Why it matters — The finding decides whether a signal from a phone maker counts as a check, and every other site facing the same law will read it. [24]

  15. 16

    Fake logistics apps steal drivers' text messages

    Researchers at Have I Been Squatted found fake Google Play pages, branded as the logistics firms CEVA and TKW, handing out an Android app dressed up as a system service. [25] The app, Corp MDM, steals new text messages, forwards calls and hides itself, and reports to its server every 30 seconds. [25] The same server hosts fake login pages and Windows malware aimed at logistics companies. [25] The researchers think the spyware was written with AI help, because of bugs that get in its own way. [25]

    Why it matters — A stolen text message is often the one-time code a bank or a work login sends. A driver who installs a fake company app hands those over. [25]

  16. 17

    Mac password-stealer poses as a crypto wallet

    Jamf, a company that manages Apple devices for businesses, found a new version of PamStealer, a program that steals passwords from Macs. [26] Earlier versions this summer posed as clipboard apps; this one uses a fake website for a crypto wallet called Wavel, which does not exist. [26] The download opens Apple's own Script Editor, which runs a hidden script that fetches the real payload. [26] The key to unlock that payload now lives on the attacker's server, so researchers cannot take the malware apart without the server's cooperation. [26]

    Why it matters — The fake site is aimed at people looking for somewhere to keep their coins, who hold exactly the passwords a thief wants most. [26]

  17. 18

    A firm hired a North Korean fraudster on purpose

    Nisos, a US firm that investigates insider risk, let a suspected North Korean applicant be hired for a remote AI engineering job in June 2025 and shipped a laptop fitted with monitoring to a Florida address. [27] The laptop opened in a closet full of other companies' computers, a laptop farm. [27] Over months the operator applied for other jobs, chatted with 22 other operators and worked with four US helpers, all from the China-North Korea border. [27] Last week the US, Japan, Australia and Germany updated their advisory: the scheme has infected 30,000 devices in over 100 countries and drained 7,000 crypto wallets. [27]

    Why it matters — The fraud starts at a hiring desk, not a firewall, which is why the advice is to retrain the people who interview. [27]

  18. 19

    Thirteen kinds of flaw in one dashcam

    CISA published an advisory on Wednesday about the Botslab G980H dashcam, listing thirteen kinds of flaw in one device, including a built-in password, a built-in encryption key, functions with no login at all, and passwords sent without encryption. [28] An attacker could get past the login, read stored data, change settings or stop the camera working. [28] The combined severity is rated 8.8 out of 10. [28]

    Why it matters — A dashcam records where a car goes, and a device with a password built into it is one that every buyer shares with every other buyer. [28]

02 Lesson why it matters

Why an exchange keeps most of its coins where even it cannot reach them fast

Bitget lost $387m from the wallets its own software could open, and nothing from the ones that need a person and a separate key.

The twist

The thief did not break into the wallets. He took over the machine that was allowed to open them, so everything that machine could open was gone in eighteen minutes, and everything it could not open is still there.

The picture

The two kinds of wallet at Bitget and what happened to each on Thursday. The line between them is drawn by the exchange, and Arkham says one drained wallet sat on the other side of it.

How it works

  1. An exchange keeps some coins online, so withdrawals pay out in seconds
  2. Its own software decides which transfers to sign
  3. A thief who takes over that software can sign transfers too
  4. Everything the software could reach goes in minutes
  5. Coins kept offline need a person and a separate key, so the same trick cannot reach them

The same force, elsewhere today

Where this chain is also running, in today's other stories.

  • Kiteworks telling customers to switch off

    A server that is switched off cannot be reached by the flaw, whatever the flaw is; the company chose six hours of nothing over six hours of exposure

  • Old Revolut records taken from DriveWealth

    The records were kept on a system people could log into, so a caller who talked their way to a login reached all of them; records kept nowhere cannot be taken

  • The overwritten maternity database

    The old database was live and reachable by a routine copying job, so one wrong setting wrote over it; the notes came back only because copies were kept elsewhere

  • Kyiv's internet after the strikes

    Utels kept its core equipment in one data centre, so one building losing power took its whole network with it

Where you've seen this

A shop

the till holds a day's takings and the safe holds the rest; a robber empties the till, and the shop opens tomorrow

A bank card

a card can spend what is in the account it is tied to, and no more; a stolen card cannot reach the savings account it was never linked to

Passwords on a phone

every password saved in the browser is one a thief with the phone can read; the ones written on paper at home are out of reach

The catch

The line between online and offline is drawn by the exchange, and only it can see where; Arkham says one of the drained wallets was one it had labelled as cold, and Bitget says its cold wallets were untouched.

And the whole of it

Everyone who keeps coins at an exchange is trusting where that line was drawn and how well the machine on the near side of it was guarded, and none of them can see either. Bitget's customers learned where the line ran from a post on X, eighteen minutes after it mattered.

03 Truth what's really going on

What is really going on

Bitget has said a great deal about the fund that will repay its customers and almost nothing about how a thief got into the system that approves its transfers. The one number anyone outside can check is the 5,500 bitcoin sitting in public wallets; the rest, including whether the North Korea claim is right, is Bitget's word.

Why it works on us — A fund that covers everything turns a $387m theft into a story about a company's strength, and the question of how the thief got in slips in behind it.

Who gains

  • Whoever took the coins — The coins were spread across seven networks, most of them in 18 minutes, and only some addresses have been frozen; the rest can be moved on before the tracing catches up. [1][4]
  • ShinyHunters — It broke into the FBI to make the bureau's May warning look wrong, and on Friday the bureau confirmed the break-in in public. [8]
  • Google and Wiz — Scan for Good puts their scanning models inside hospitals and rail operators for free, in the same month their own AI agents were caught hacking other companies' sites. [18]
  • Apple — Ofcom's investigation asks how Aylo used Apple's age signal, and says outright that it is not examining how Apple's own system works. [24]
  • Mandiant and SlowMist — Both were hired within a day of the theft to run the outside investigation, and Chen says every dollar and every decision will be accounted for in full. [3][2]

Who pays

  • Bitget's customers — Their balances read correctly but they cannot withdraw, and Bitget has given no date for when they can. [3][1]
  • Former Revolut customers — Their names, addresses, jobs and citizenship were held by a broker they no longer used, because DriveWealth says the rules made it keep them. [15]
  • FBI staff and their families — Home addresses, emergency contacts and medical evaluations are in the sample files, and the gang says it will publish within four days. [9][10]
  • About 100,000 households around Kyiv — Their internet went down when the data centres holding their providers' equipment were hit, and the missile warnings travel over that internet. [21]
  • Companies running Kiteworks — They were asked to switch off a system they use to send confidential files for six hours on a Saturday, with no flaw named. [12]
  • Women treated at Nottingham's maternity unit from 2011 to 2022 — The record of who viewed their files is gone, so most of them can no longer find out whether anyone did. [19]

What nobody knows yet

Open questions from across today’s stories — ours included.

  • 01

    How much Bitget actually lost.

    Bitget said $351.6m on Thursday and $387.5m on Friday after finding losses on Zcash and TRON; Arkham's own tally was about $350m and Reuters reported roughly $350m. [1][4][6]

  • 02

    Whether one of the emptied wallets was a cold wallet.

    Arkham says $153m in XRP left a wallet it had identified as a Bitget cold wallet. Chen says the cold wallets were untouched. Both cannot be right unless Arkham's label was wrong. [4]

  • 03

    How the attacker got into Bitget's wallet service.

    Bitget says the method of intrusion is still under investigation and has published nothing on it. [1]

  • 04

    Whether North Korea did it.

    Chen cites internet addresses, behaviour and on-chain patterns but named no group and published no evidence; blockchain analysts say the funds link to past Lazarus thefts. [5][2]

  • 05

    Whether the FBI's hole was in its own systems or a contractor's.

    The FBI told The Register on Friday that the point of breach is still undetermined. [8]

  • 06

    What flaw Kiteworks is worried about.

    There is no CVE number, no patch and no technical detail; the company says only that it received credible intelligence from federal agencies. [12]

  • 07

    Who is attacking SharePoint and how many organisations were hit.

    Microsoft confirmed attacks as of 25 September and disclosed nothing about who, when, or what was done inside. [13]

  • 08

    What Astrana lost and whether ransomware was used.

    Its filing names no patient count and no data type, and the company did not answer the ransomware question. [16]

  • 09

    Who looked at Nottingham's maternity records between 2011 and 2022.

    The access log was overwritten with the database and the trust says it cannot fully restore it. [19]

04 Hope carry this

Bitget says a fund of 5,500 bitcoin, held in wallets anyone can inspect, will repay every customer in full. Within a day the rival exchanges Binance, Bybit and MEXC had offered help tracing the coins, and some networks had frozen the thief's addresses.

Also true today

  • Nottingham University Hospitals recovered the notes, observations and test results from the maternity database it overwrote, and no current patient was affected.
  • Google's bug-hunting AI found serious flaws at hospitals, a town council and a public rail operator, and each one was handed to a person to check and fix.
  • Utels, a Kyiv internet provider whose main data centre lost power in Wednesday's strikes, had most of its customers back online within about two hours.

Across the beats