Crypto exchange Bitget suspects North Korean hackers are responsible for a security breach affecting approximately $351.6 million in digital assets, according to CEO Gracy Chen. Preliminary investigation results revealed internet protocol addresses associated with VPN services previously utilized by a North Korean hacking group, and the attack pattern resembled earlier operations attributed to the country. The intrusion involved unauthorized transfers from hot and warm wallets on Thursday afternoon, while cold wallets remained secure. Affected assets included ether, XRP, USDT, USDC, Avalanche, and BNB across multiple networks, including Ethereum, XRP Ledger, Avalanche, BNB Smart Chain, and Arbitrum. Earlier on-chain estimates of $183 million were revised upward after analyses failed to capture activity across all affected blockchains.

Chen stated that the attacker breached a critical backend wallet system to spoof transfer information and trigger Bitget’s authorization-signing process, though private key compromise has been ruled out. The breach was contained to prevent further outflows, but withdrawals remain suspended while technical teams repair and reinforce systems; deposits and trading continue normally. The company asserts customer balances are accurate and losses are fully covered by its User Protection Fund, which holds more than $464 million. Bybit CEO Ben Zhou offered assistance, noting his team is updating the LazarusBounty platform to help trace stolen funds, reciprocating support provided by Bitget following Bybit’s $1.5 billion hack in February 2025.