Major Players In Crypto Hacked

Crypto's Billion-Dollar Blind Spot: Inside the Bitget Heist and the Revolut Extortion Plot

There is a particular kind of vertigo that comes from watching $390mn vanish from a company's books in the space of a few hours, and yet in the crypto world this has become almost routine. Bitget, the world's fifth-largest exchange by spot trading volumes, discovered on a Thursday evening that hackers had drained $351.6mn from customer wallets, a figure that crept up to $387.5mn by the following day once the exchange had completed "a more complete accounting of transfers". It was, by some distance, the largest single crypto theft of 2026, and it arrived with a signature that has become depressingly familiar: methods "highly consistent" with North Korean hacking groups.

I have written before about how the crypto industry has matured in fits and starts, gaining institutional respectability while never quite shaking off its reputation as the Wild West of finance. The Bitget hack, and a second, altogether stranger incident involving Revolut, illustrate why that reputation persists. Between them, they show the two faces of modern crypto crime: the brute-force theft of digital assets, and the quieter, more patient business of stealing the data needed to find the people who hold them.

How Bitget Was Breached

Bitget's chief executive, Gracy Chen, described the mechanics of the attack with unusual candour. The hackers had "compromised a critical back-end system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorisation process to move funds out". In plain terms, they did not smash down the front door so much as forge the keys and walk through it. Tokens including ether, XRP and the stablecoins USDC and USDT were siphoned across multiple blockchains, including Ethereum, XRP Ledger and Base.

To Bitget's credit, the exchange froze customer withdrawals within minutes and moved quickly to reassure users that its User Protection Fund, then holding more than $464mn, would cover the losses. That is precisely the kind of contingency planning that separates a survivable incident from a reputational catastrophe, and it is worth noting given how many exchanges have folded entirely after similar breaches.

A Pattern That Keeps Repeating

Anyone who has followed this beat for a while will recognise the North Korean fingerprint immediately. Blockchain analytics firm Chainalysis found that North Korean-linked hackers stole roughly $2.02bn in crypto through 2025 alone, of which the bulk came from a single attack on Bybit in February 2025, where 400,000 ether and staked ether worth around $1.5bn were drained from the Dubai-based exchange's cold wallet. That remains the largest crypto heist in history, and Bybit is still fighting to recover it, having filed a civil racketeering lawsuit against the DPRK, its Reconnaissance General Bureau and the notorious Lazarus Group, and securing a US court order freezing some of the stolen assets. So far the exchange has clawed back only $48.4mn, with over 90 per cent of the haul still untraceable.

That is the grim arithmetic of crypto crime: theft is instantaneous, recovery is generational. TRM Labs' figures for 2026 put total losses across the industry at $1.73bn across 333 separate incidents before the Bitget hack was even added to the tally, with the $319mn Liquid Network hack and $292mn KelpDAO exploit both contributing to a year that has been unusually punishing even by crypto's own low standards. North Korean-linked operators accounted for roughly 76 per cent of all hack value through the first four months of 2026 alone, largely on the back of just two attacks. Pyongyang's hacking units, widely believed to fund the regime's weapons programme, have effectively industrialised cyber theft as a line of state revenue.

When the Target Becomes the Person, Not the Platform

The second incident I want to draw attention to is more insidious precisely because it involves no hacking of any exchange's core systems at all. Hackers operating under the pseudonym "iamnotavillain" claim to have spent months posing as Italian law enforcement, using a compromised government email system called PEC (Posta Elettronica Certificata) to request confidential customer data from Revolut. According to messages sent to the Financial Times, Revolut "was complying like a 'good boy'," handing over addresses, phone numbers and transaction histories for what would eventually amount to almost 700 customer accounts.

Crucially, these were not random targets. The group told the FT they had used on-chain analysis to identify Revolut accounts holding significant crypto balances, deliberately hunting for what they called "crypto whales". Most of those affected were based in Switzerland and France, though customers in 31 other countries, including the UK, Germany and Spain, also had their data exposed. Revolut insists its own systems were never breached and that the fault lies entirely with the abuse of an "official, state-regulated legal communication channel", which is technically true but will offer little comfort to any customer whose home address is now sitting on a hacker's spreadsheet.

Why This Matters Beyond the Crypto Bubble

What connects Bitget and Revolut is not the method but the motive: crypto's transparency, ironically, is what makes its holders so easy to identify and target. Every wallet balance is visible on a public ledger, meaning that once an attacker links a wallet to a name, they have effectively drawn a target on that person's back, whether the goal is direct theft or old-fashioned extortion. Italian opposition lawmaker Giulia Pastorella put it well when she called the breach "the tip of the iceberg" and asked how many other companies might have fallen for the same scam.

For an industry that has spent the best part of a decade trying to convince regulators, banks and ordinary savers that it has grown up, 2026 has been a sobering reminder that the fundamentals have not changed much. The technology has become faster and more liquid, the institutional money has arrived in earnest, but the security architecture protecting it is still being tested, breached and patched in real time, often at a cost measured in hundreds of millions of dollars. Until custody, verification and data-sharing protocols catch up with the scale of money now flowing through crypto markets, exchanges and their customers alike will remain a target that state-backed hackers and opportunistic extortionists alike simply cannot resist.


RECENT NEWS

Meta Rises On The Back Of Connect

Meta’s AI Moment: Can Muse Justify the Bill?There are moments in the market when investors stop asking whether a compa... Read more

A Buyout Of Another British Fintech

Monzo and Nubank: A Marriage of Digital Banking AmbitionMonzo’s reported discussions with Brazil’s Nubank have the p... Read more

Does The West Have A Problem With Government Bonds

If you have been following the financial pages over the past few weeks, one theme has begun to stand out from the usual ... Read more

Meta Faces Its Big Tobacco Moment

For years, the largest social media companies have faced accusations that their platforms damage young people. They have... Read more

Sequencing Resilience: Defining A New Category

Why the industry must treat Retirement Portfolio Resilience as a distinct allocation alongside retirement income solutio... Read more

Crypto.com's $20bn Moment

Crypto.com has become the latest crypto exchange to attract serious money from a major Wall Street market-maker, with Ci... Read more