Bitget Investigates Massive $352 Million Security Breach Linked to North Korean Actors
The cryptocurrency exchange Bitget is currently investigating a significant security breach that resulted in the unauthorized transfer of approximately $351.6 million in digital assets. CEO Gracy Chen confirmed that the incident involved 19 separate transfers from the platform’s hot and warm wallet infrastructure, while cold storage systems remained unaffected and secure.
Preliminary findings from the ongoing investigation point toward potential involvement by North Korean hacking groups. Investigators identified internet protocol addresses associated with VPN services previously utilized by state-sponsored actors from the region. Furthermore, the tactical execution of the attack mirrors patterns observed in previous high-profile operations attributed to the same entities. The breach occurred after attackers compromised a backend wallet system, allowing them to spoof transfer data and bypass authorization-signing protocols.
Despite the scale of the theft, which impacted various assets including Ether, XRP, USDT, USDC, Avalanche, and BNB, Bitget has moved to reassure its user base. The company confirmed that all losses are fully covered by its User Protection Fund, which currently holds over $464 million. While withdrawals have been temporarily suspended to allow technical teams to reinforce system security, deposits and standard trading activities remain operational.
Industry peers have begun offering support, with Bybit pledging to assist in tracing the stolen funds through its LazarusBounty platform. Bitget expects to restore full withdrawal functionality in the coming days as the investigation into the specific intrusion method continues.
Key Takeaways
- Bitget suffered a $351.6 million hack involving unauthorized transfers from its hot and warm wallet infrastructure.
- The exchange suspects North Korean state-sponsored hackers based on IP patterns and operational similarities to past attacks.
- Customer funds are protected by a $464 million User Protection Fund, and the company has contained the breach.
Editor’s Analysis & Impact
This incident highlights the persistent vulnerability of centralized exchange infrastructure to sophisticated, state-sponsored cyber threats. The ability of attackers to spoof backend wallet systems suggests a high level of technical proficiency, moving beyond simple phishing or private key theft. For the broader crypto industry, this event underscores the critical necessity of robust, multi-layered security protocols and the importance of maintaining substantial insurance or protection funds to preserve market confidence. As North Korean-linked groups continue to target digital asset platforms to circumvent international sanctions, exchanges will likely face increased regulatory pressure to adopt more stringent security audits and real-time monitoring. The collaborative response from other industry players like Bybit signals a growing trend of collective defense within the crypto ecosystem, which may become a standard practice to mitigate the impact of future large-scale breaches.
Frequently Asked Questions
Q: Are user funds safe following the Bitget hack?
A: Yes, Bitget has stated that all losses are fully covered by its User Protection Fund, which contains over $464 million, ensuring that customer balances remain secure.
Q: Can users still trade on the Bitget platform?
A: While withdrawals are currently suspended to allow for system reinforcements, deposits and standard trading activities remain fully operational for users.