What happened
On September 24, 2026, Singapore-headquartered crypto exchange Bitget disclosed that hackers had stolen roughly $387.5 million after breaching a backend wallet system, exploiting it to push through unauthorized transfers of ETH, XRP, USDC and other assets. CEO Gracy Chen told a company town hall that IP addresses matching North Korea-linked VPNs and attack patterns resembling earlier North Korean hacks pointed to North Korea's Lazarus Group, while analysts including Elliptic traced on-chain links between the stolen funds and earlier DPRK thefts. Withdrawals were suspended while Bitget worked with blockchain security firms Mandiant and SlowMist, and Chen said the exchange's $464 million User Protection Fund would cover customer losses in full (The Record).
That response is the right one operationally: fast disclosure, an existing insurance-style backstop, and cooperation with named forensics firms rather than silence. It's also, unfortunately, routine. This is what a Lazarus-scale heist now looks like on arrival.
The 'Singapore-based' label is doing less work than it sounds
Here is the detail that matters for policy, not just the incident report: Bitget is not licensed, approved, registered or authorized by the Monetary Authority of Singapore, a status the exchange itself has confirmed. It restricts Singapore residents from its platform and lists the country among its prohibited jurisdictions in its own terms of use. MAS, meanwhile, includes Bitget on its Investor Alert List — the register of entities the public might wrongly assume carry Singapore regulatory approval (crypto.news).
So when headlines describe a "Singapore-based" exchange losing $387 million, the accurate reading is narrower: a firm headquartered and staffed in Singapore, serving customers almost entirely outside it, operating entirely outside MAS's supervisory perimeter. That is not an oversight MAS failed to catch — it is the outcome MAS's 2025 licensing framework for digital token service providers was explicitly designed to produce. Under that regime, DTSPs serving only overseas customers must be licensed to keep operating from Singapore soil, and MAS said plainly it "has set the bar high for licensing and will generally not issue a licence," citing money-laundering risk and its inability to effectively supervise activity whose customers and consequences sit entirely abroad (MAS media release). Firms in Bitget's position were expected to restructure, relocate substantive operations, or continue unlicensed and unprotected by any MAS backstop. Bitget chose the third path.
The steelman: this looks like exactly the gap regulators warned about
The case for tighter rules writes itself here. A firm can headquarter in a jurisdiction with a strong regulatory brand, market that association implicitly, and still leave customers with none of the deposit protections, cyber-resilience audits, or incident-reporting duties that MAS-licensed payment institutions must meet under the Payment Services Act. When a nation-state actor extracts $387.5 million through a backend wallet vulnerability, the argument that someone should have been auditing that infrastructure before the fact is not unreasonable. Cybersecurity researchers have also noted a broader pattern worth taking seriously: Chainalysis's 2026 Crypto Crime Report found DPRK-linked hackers stole roughly $2 billion across crypto platforms in 2025 alone, the single largest annual total on record, built substantially on the record $1.5 billion Bybit theft in February 2025 that the FBI formally attributed to the same Lazarus/TraderTraitor cluster (Chainalysis; FBI/IC3). That is not a one-off criminal event; it is a sustained, state-directed extraction campaign, and treating each hack as an isolated corporate failure understates the pattern.
Why the proportionate answer isn't a broader licensing net
But MAS already ran this cost-benefit analysis, and its conclusion holds up under this incident rather than being undermined by it. Extending Singapore licensing to every exchange with a local office but an offshore customer base would either (a) push firms like Bitget to relocate their headquarters to jurisdictions with even less capacity to supervise them, achieving nothing for the customers actually at risk, or (b) force MAS to attempt extraterritorial supervision of activity and infrastructure it structurally cannot inspect — the exact incapacity MAS cited as its reason for restraint. Licensing regimes are built to police the relationship between a regulator and the customers inside its jurisdiction; they are a poor tool against an adversary that doesn't care which jurisdiction's name is on the login page.
The interventions that actually worked here run through a different channel entirely: the FBI's public address-blocking alerts after Bybit, the freezing of Lazarus-linked wallets by other exchanges within hours of the Bitget breach, and Bitget's own pre-funded loss-absorption reserve. None of those required a Singapore licence. Proportionate regulation, applied honestly, means matching the tool to the actual point of leverage — sanctions enforcement and laundering-rail interdiction for a state actor MAS cannot license its way out of, paired with disclosure requirements robust enough that a firm's true regulatory status is never ambiguous to the customers relying on it. MAS's Investor Alert List is that second piece doing its job quietly; the fix here is making sure exchanges stop letting geography imply protections they were never granted.