Bitget points to North Korea after $387.5m crypto theft
Bitget says suspected North Korean attackers stole $387.5 million through compromised security software, raising fresh questions about exchange wallet controls.
Onchain Report Newsroom#268cff2 min read
Bitget says it suspects North Korean attackers stole $387.5 million from its exchange, raising fresh questions about how hackers can reach crypto wallet systems. The exchange’s CEO, Gracy Chen, cited suspicious IP addresses linked to VPN infrastructure previously used by North Korean hacker groups, Tom’s Hardware reported. The attribution remains a suspicion, not a confirmed finding.
How much did Bitget lose, and when?
Bitget detected unauthorized transfers at 18:31 UTC on September 24 from some of its hot and warm wallets, which are used to hold funds for faster access. It first put the affected amount at $351.6 million, then revised it to $387.5 million after counting assets on Zcash and TRON that were missing from the initial estimate. The exchange said the revised figure reflects a fuller count of the same incident, not additional transfers.
The affected assets included XRP, ETH, USDT, ZEC, USDC, BNB, AVAX and TRX across several blockchain networks. Bitget said its cold wallets, which hold assets offline, were not affected, and that private keys were not compromised.
How did attackers get transfers approved?
Bitget’s latest update says independent investigations by Mandiant and SlowMist found that compromised third-party security products enabled unauthorized access to the exchange’s wallet environment. Bitget says the attackers used that access to steal intranet credentials, send forged withdrawal commands and bypass risk checks. Its September 30 update on the Mandiant and SlowMist reports says their findings broadly match the attack path Bitget had described. The public update does not say those investigators confirmed who carried out the attack.
The exchange says it identified and fixed the vulnerability. It paused withdrawals after detecting the transfers and began restoring them in phases from September 28, while deposits and trading continued.
What does the North Korea link rest on?
Chen said the IP addresses seen during the attack were tied to VPN infrastructure previously used by North Korean hacker groups. That clue led Bitget to name North Korea as its primary suspect. It does not establish who controlled the addresses or prove that a North Korean group carried out the theft.
Bitget said its User Protection Fund, then valued at more than $464 million, could cover the reported loss. The company also launched a recovery bounty for funds that can be frozen or returned. The breach highlights the risk that attackers can reach exchange wallets through connected systems, even when private keys stay secure.