USStockArticle is online

Bitget Says North Korean Actors Likely Behind $352M Crypto Breach

Mr. W
Bitget Says North Korean Actors Likely Behind $352M Crypto Breach

Preface


Context: Crypto exchange Bitget announced a major security incident that affected roughly $351.6 million in digital assets. The company has shared preliminary investigative findings that point to tactics and infrastructure historically associated with North Korean-linked hacking groups. This article summarizes the available facts, describes what Bitget has disclosed about the breach, and explains the immediate actions the exchange took to contain the incident and protect customer funds.



Lazy bag


Key takeaways: Bitget identified internet protocol addresses tied to VPN services previously linked to North Korean groups and observed attack patterns resembling earlier operations. The intrusion affected multiple hot and warm wallets but left cold storage intact. Bitget says private keys were not compromised, withdrawals are suspended temporarily, and customer losses are covered by its User Protection Fund. Investigations remain ongoing.



Main Body


On discovering unauthorized transfers, Bitget moved quickly to investigate and contain a complex security incident that resulted in approximately $351.6 million in assets being moved from parts of its online wallet infrastructure. According to statements from Bitget CEO Gracy Chen during a livestream, initial forensic work uncovered internet protocol addresses associated with virtual private network (VPN) services that have been connected previously to North Korean-affiliated cybercrime groups. Additionally, the attack's operational pattern bore similarities to past incidents attributed to those state-linked actors.



Bitget reported that the breach involved 19 transfers originating from portions of its hot and warm wallet systems. The exchange emphasized that its cold wallets — offline storage typically used to secure long-term holdings and large reserves — remained secure and were not affected. The mix of affected assets included tokens and coins across multiple networks: ether (ETH), XRP, USDT, USDC, Avalanche (AVAX) and BNB, spanning the Ethereum, XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum ecosystems. Early on-chain external estimates initially pegged the outflows at about $183 million, but Bitget noted those calculations did not fully capture activity across every affected blockchain, leading to the higher figure the company disclosed.



Bitget’s security team described a specific attack vector in which a critical backend wallet system was breached and used to fabricate transfer information. That spoofed information then triggered the exchange's authorization-signing process, enabling unauthorized transfers to proceed. Importantly, Bitget has publicly stated that a compromise of private keys has been ruled out, indicating the attacker exploited internal systems rather than extracting raw key material from secure storage.



In response to the incident, Bitget contained the breach to prevent further unauthorized outflows and suspended withdrawals while engineering teams repaired and reinforced the affected systems. The company kept deposits and trading operations operational to minimize disruption for users. CEO Gracy Chen said she could not promise a precise timeline for restorations but estimated withdrawals would likely be reinstated within hours or days rather than weeks, based on the pace of remediation and ongoing technical validation.



Bitget also reassured customers that account balances remain accurate and that the financial impact of the breach is covered by the exchange’s User Protection Fund, which reportedly contains more than $464 million — enough to absorb the loss without directly affecting user holdings. This kind of fund is intended to provide short-term protection and help maintain market confidence while forensic and legal processes continue.



The broader crypto community has shown rapid cooperative behavior in response. Bybit CEO Ben Zhou stated that his team was ready to assist Bitget and announced updates to Bybit’s LazarusBounty tracing platform to support tracking of stolen funds. The solidarity follows a previous instance in which Bitget assisted Bybit after a large hack earlier in the year.



Investigations into the exact intrusion method remain underway. Bitget has been cautious to avoid definitive attribution until further technical details are confirmed, even while flagging indicators consistent with North Korean-linked activity such as the use of VPN endpoints and operational similarities to historically attributed campaigns. Attribution in large-scale cyber incidents is often complex and requires cross-verification from multiple forensic sources, blockchain tracing, and intelligence sharing among exchanges and law enforcement.



For affected users and observers, the incident highlights several important considerations: the continuing attractiveness of centralized exchange hot wallets to well-resourced attackers, the role of layered defenses (including protecting critical backend systems, robust monitoring and transactional authorization controls), and the importance of contingency reserves or protection funds that can cover losses to maintain customer trust. It also underscores the evolving interplay between blockchain transparency — which enables public tracing of transfers — and sophisticated obfuscation techniques employed by attackers to move and launder stolen assets across multiple chains and mixing services.



Looking ahead, the industry can expect continued collaboration among exchanges, blockchain analytics firms and law enforcement to trace proceeds and seek recovery where possible. Simultaneously, exchanges may accelerate hardening of backend infrastructure, refine authorization workflows, and expand routine red-team testing to anticipate similar vectors. For individual users, best practice remains diversifying custody strategies, considering non-custodial storage for large holdings, and monitoring exchange communications closely for restoration timelines.



In summary, Bitget’s disclosure provides an early, detailed window into a multi-chain theft that the company attributes — based on initial evidence — to actors using infrastructure linked to North Korean campaigns. While some specifics remain under technical investigation, prompt containment, public transparency about affected assets and the existence of a protection fund have been central to Bitget’s immediate response.



Key Insights Table



































Aspect Description
Scope of Loss Approximately $351.6 million in assets were moved from hot and warm wallets across multiple blockchains.
Attribution Indicators Preliminary evidence includes VPN-linked IP addresses and attack patterns consistent with groups previously tied to North Korea.
Compromised Systems A critical backend wallet system was breached, allowing spoofed transfer data to trigger authorization processes; cold wallets unaffected.
Private Keys Bitget stated private key compromise has been ruled out, suggesting internal system exploitation rather than key exfiltration.
User Impact Withdrawals suspended temporarily; deposits and trading continue; customer balances claimed intact and losses covered by a protection fund.
Industry Response Other exchanges and tracing platforms have offered assistance and coordination to trace stolen funds and strengthen defenses.


Note: This article is a restatement of Bitget’s public disclosures and early investigation findings. Attribution and technical details may evolve as forensic teams complete their work and further intelligence is shared.

Last edited at:2026/9/25