Bitget CEO Gracy Chen stated that preliminary investigations suggest North Korean hackers are responsible for the exchange’s recent $351.6 million security breach. During a live Q&A on X following the incident, Chen noted that security teams identified IP addresses matching VPN services used by a specific Democratic People’s Republic of Korea (DPRK) group. She emphasized that the pattern closely resembles previous attacks attributed to North Korean actors and dismissed theories that the breach was an inside job.

The attack involved unauthorized transfers affecting portions of Bitget’s hot and warm wallet infrastructure, though Chen clarified that the attackers did not forge user withdrawal requests or compromise private keys associated with cold wallets. Investigators are currently working to determine which systems were breached and how access was gained. While some stolen funds have been recovered through collaboration with blockchain foundations and partners, the exact amount remains unspecified. Withdrawals at Bitget remain suspended as the exchange continues its recovery efforts and forensic analysis.