DKDKCISSPSearch
AI SecurityDEVELOPING

IAM for AI agents: A Practical Enterprise Framework

AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority.

DKCISSP News DeskThe Hacker News28 Sept 2026, 11:50 pm
IAM for AI agents: A Practical Enterprise Framework
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

Chen blamed the incident on North Korean hackers, citing on-chain analysis and IP behavior patterns, adding that they breached a critical backend system within Bitget wallet infrastructure and used it to spoof transaction data, triggering the exchange's authorization process to move funds out of compromised hot/warm wallets.

On Friday, Bitget updated the amount of assets stolen in the attack, saying that $387.5 million was transferred to attacker-controlled addresses , according to the latest on-chain tracing and transaction classification.

In a September 28 statement on X, Bitget said a flaw in a third-party security product gave the attacker high-level internal credentials, which were then used to send fraudulent withdrawal commands that bypassed its risk controls.

Bitget did not disclose any details on how the attack took place, but said it has enlisted the help of Google-owned Mandiant and SlowMist for a third-party investigation.

Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million.

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.

Trading and deposits continue to operate." Bitget suspended all withdrawals on Thursday after its security systems flagged multiple unauthorized transfers from a limited number of crypto wallets and discovered that attackers had stolen $351.6 million from its hot and warm wallets.

The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday.

The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system.

According to The Block, she described the flaw as a zero-day, the term for a vulnerability that attackers exploit before its maker has a fix.

What happened

Chen blamed the incident on North Korean hackers, citing on-chain analysis and IP behavior patterns, adding that they breached a critical backend system within Bitget wallet infrastructure and used it to spoof transaction data, triggering the exchange's authorization process to move funds out of compromised hot/warm wallets.

On Friday, Bitget updated the amount of assets stolen in the attack, saying that $387.5 million was transferred to attacker-controlled addresses , according to the latest on-chain tracing and transaction classification.

What changed

In a September 28 statement on X, Bitget said a flaw in a third-party security product gave the attacker high-level internal credentials, which were then used to send fraudulent withdrawal commands that bypassed its risk controls.

Bitget did not disclose any details on how the attack took place, but said it has enlisted the help of Google-owned Mandiant and SlowMist for a third-party investigation.

Who is affected

Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million.

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.

Why it matters

Trading and deposits continue to operate." Bitget suspended all withdrawals on Thursday after its security systems flagged multiple unauthorized transfers from a limited number of crypto wallets and discovered that attackers had stolen $351.6 million from its hot and warm wallets.

The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday.

Technical details

The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system.

According to The Block, she described the flaw as a zero-day, the term for a vulnerability that attackers exploit before its maker has a fix.

British blockchain analytics firm Elliptic estimated in February 2025 that North Korean hackers have "stolen over $6 billion in crypto assets since 2017." Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Response

Bitget's September 26 withdrawal update said the vulnerability behind the incident had been identified and remediated, while its investigation with Mandiant and blockchain security firm SlowMist continued.

Bitget CEO Gracy Chen described the attack on Monday in a livestream, in an interview with The Block , and in comments to Cointelegraph .

What security teams should do

Identity and access management (IAM) for AI agents treats each agent as a non-human identity with a human owner, a defined purpose, scoped authorization, an expiration, and continuous monitoring.

TRM Labs , a blockchain analytics firm, said last week that it found overlaps between the stolen funds and wallets used to launder earlier North Korean thefts.

Attribution

The Hacker News: AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority.

The Hacker News: The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday.

Infosecurity Magazine: Withdrawals on the Bitcoin network reopened at 08:00 UTC on September 28 after additional security checks.

BleepingComputer: Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.

MORE IN AI SECURITY

More cybersecurity reporting

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted ServersThe Hacker News · 2 Oct 2026, 11:03 pmGitLab warns of critical RCE vulnerability in AI Gateway serviceBleepingComputer · 2 Oct 2026, 9:50 pmMicrosoft: AI Cuts Post-Compromise Attack Time to MinutesInfosecurity Magazine · 2 Oct 2026, 7:45 pmAI agents keep access to company data after their work is done - Help Net SecurityHelp Net Security · 2 Oct 2026, 10:00 am