Crypto platform Bitget suspects North Korea is responsible for $352 million hack
Key Points
- Investigators identified IP addresses linked to VPN services previously used by a North Korean hacking group, and the attack pattern resembled earlier operations attributed to North Korea
- The breach affected multiple cryptocurrencies including ether, XRP, USDT, USDC, Avalanche and BNB across various blockchain networks, with withdrawals suspended but deposits and trading continuing normally
- Bitget's User Protection Fund with more than $464 million will fully cover the losses, and the company expects to restore withdrawals within hours or days rather than weeks
AI Summary
Summary: Bitget Crypto Exchange Suffers $352 Million Suspected North Korean Hack
Key Incident Details:
Cryptocurrency exchange Bitget experienced a major security breach resulting in approximately $351.6 million in stolen digital assets. The platform detected 19 unauthorized transfers from its hot and warm wallet infrastructure on Thursday afternoon (U.S. time), while cold wallets remained secure.
Attribution and Attack Method:
CEO Gracy Chen stated that investigators identified IP addresses linked to VPN services previously associated with North Korean hacking groups. The attack pattern resembled prior operations attributed to North Korea. The attacker breached a critical backend wallet system, spoofed transfer information, and triggered Bitget's authorization-signing process. However, Chen confirmed that private key compromise has been ruled out.
Affected Assets:
Stolen cryptocurrencies included ether, XRP, USDT, USDC, Avalanche, and BNB across multiple blockchain networks (Ethereum, XRP Ledger, Avalanche, BNB Smart Chain, and Arbitrum). Some third-party analyses estimated lower outflows at $183 million, though Bitget maintains these didn't capture all affected blockchains.
Customer Impact and Recovery:
Bitget has suspended withdrawals pending system repairs, though deposits and trading continue normally. Chen indicated withdrawals could resume within hours or days, not weeks. The company assured customers that all losses are fully covered by its User Protection Fund, which holds over $464 million—sufficient to cover the breach.
Industry Cooperation:
Bybit CEO Ben Zhou offered assistance, updating the LazarusBounty platform to help trace stolen funds, reciprocating support Bitget previously provided during Bybit's own security incident.
Market Implications:
This breach underscores ongoing cybersecurity vulnerabilities in cryptocurrency exchanges and highlights persistent threats from state-sponsored hacking operations targeting digital asset platforms.
Model Analysis Breakdown
| Model | Sentiment | Confidence |
|---|---|---|
| GPT-5-mini | Bearish | 75% |
| Claude 4.5 Haiku | Bearish | 82% |
| Gemini 2.5 Flash | Neutral | 85% |
| Consensus | Bearish | 80% |