Bitget CEO Gracy Chen stated that preliminary investigations suggest North Korean hackers are responsible for the exchange’s recent $351.6 million security breach. During a live Q&A on X following the incident, Chen noted that security teams identified IP addresses matching VPN services used by a specific Democratic People’s Republic of Korea (DPRK) group. She emphasized that the pattern closely resembles previous attacks attributed to North Korean actors and dismissed theories that the breach was an inside job.
The attack involved unauthorized transfers affecting portions of Bitget’s hot and warm wallet infrastructure, though Chen clarified that the attackers did not forge user withdrawal requests or compromise private keys associated with cold wallets. Investigators are currently working to determine which systems were breached and how access was gained. While some stolen funds have been recovered through collaboration with blockchain foundations and partners, the exact amount remains unspecified. Withdrawals at Bitget remain suspended as the exchange continues its recovery efforts and forensic analysis.
The attribution of this significant theft to state-sponsored actors underscores the persistent threat landscape facing centralized exchanges, particularly regarding infrastructure vulnerabilities in hot and warm wallets. By explicitly ruling out internal collusion and highlighting the direct transfer method rather than forged withdrawals, Bitget aims to maintain user trust while acknowledging a sophisticated external intrusion. This distinction is critical for institutional clients assessing counterparty risk, as it suggests the breach exploited technical system flaws rather than human error or insider malfeasance, shifting the focus entirely to cybersecurity resilience and third-party audit standards.
Market structure implications arise from the suspension of withdrawals and the ongoing uncertainty regarding fund recovery. The involvement of North Korean groups, linked to billions in prior crypto thefts including the Bybit incident, indicates that these actors possess advanced capabilities to bypass standard security protocols. For the broader industry, this event may accelerate regulatory scrutiny on custody solutions and prompt exchanges to re-evaluate their asset segregation strategies. Observers will watch for further forensic details on the compromised systems, as understanding the entry vector is essential for preventing similar breaches across the sector.


