In a significant cybersecurity breach, the cryptocurrency exchange Bitget has reported the theft of approximately $351.6 million in digital assets. The attack is suspected to be connected to North Korean cybercriminals, as the techniques employed closely mirror those used by known threat actors from the region.
Investigation and Attribution
Bitget CEO Gracy Chen disclosed in a recent statement that the patterns of IP behavior and on-chain analysis indicate a strong resemblance to tactics employed by North Korean hacker groups. While specific organizations were not named, the attack methodology aligns with prior incidents attributed to these state-sponsored hackers.
The breach has been communicated to the appropriate authorities for further investigation. Despite the lack of detailed evidence disclosure, Bitget is actively collaborating with cybersecurity firms Mandiant and SlowMist to delve deeper into the breach’s specifics.
Impact on Bitget’s Operations
Established in 2018, Bitget operates a centralized exchange for both spot and derivatives crypto trading. It also manages the Bitget Wallet, a self-custodial wallet that fortunately remains unaffected due to its separate infrastructure. The unauthorized transactions were detected on September 24, involving funds from a limited number of the exchange’s hot wallets, while the cold wallets remained secure.
The stolen assets, including cryptocurrencies such as ETH, XRP, BNB, AVAX, USDT, and USDC, were distributed across various blockchains. With XRP representing the largest loss on a single chain, some blockchain foundations have taken proactive measures by freezing wallet addresses associated with the breach.
Details of the Breach
Bitget has acknowledged the complexity of the breach, noting that the hacker gained access to a critical backend system within its wallet infrastructure, enabling fraudulent approvals for transfers. Importantly, the integrity of private keys was not compromised during the incident, highlighting the sophistication of the attack strategy employed.
This breach is part of a broader pattern of North Korean state-sponsored cybercriminal activities targeting cryptocurrency exchanges. The FBI has previously implicated North Korea in a massive heist from Bybit in February 2025, where approximately $1.5 billion was stolen.
As the investigation continues, the cryptocurrency community remains vigilant, emphasizing the importance of enhanced security measures to mitigate the risks posed by increasingly sophisticated cyber threat actors.
