Crypto exchange Bitget suspects North Korean hackers are responsible for a security breach affecting approximately $351.6 million in digital assets, according to CEO Gracy Chen. Preliminary investigation results revealed internet protocol addresses associated with VPN services previously utilized by a North Korean hacking group, and the attack pattern resembled earlier operations attributed to the country. The intrusion involved unauthorized transfers from hot and warm wallets on Thursday afternoon, while cold wallets remained secure. Affected assets included ether, XRP, USDT, USDC, Avalanche, and BNB across multiple networks, including Ethereum, XRP Ledger, Avalanche, BNB Smart Chain, and Arbitrum. Earlier on-chain estimates of $183 million were revised upward after analyses failed to capture activity across all affected blockchains.
Chen stated that the attacker breached a critical backend wallet system to spoof transfer information and trigger Bitget’s authorization-signing process, though private key compromise has been ruled out. The breach was contained to prevent further outflows, but withdrawals remain suspended while technical teams repair and reinforce systems; deposits and trading continue normally. The company asserts customer balances are accurate and losses are fully covered by its User Protection Fund, which holds more than $464 million. Bybit CEO Ben Zhou offered assistance, noting his team is updating the LazarusBounty platform to help trace stolen funds, reciprocating support provided by Bitget following Bybit’s $1.5 billion hack in February 2025.
The attribution of this $351.6 million loss to North Korean actors underscores the persistent threat landscape facing centralized exchanges, particularly regarding infrastructure vulnerabilities rather than just user-side phishing. While the containment of the breach and the ruling out of private key compromise are positive operational signs, the reliance on a User Protection Fund highlights the ongoing tension between regulatory expectations for segregated custody and the practical realities of hot wallet liquidity management. The incident demonstrates how sophisticated state-linked groups can exploit backend authorization processes, challenging the assumption that multi-layered wallet architectures provide absolute immunity against targeted social engineering or system-level intrusions.
From an institutional adoption perspective, the swift response by competitors like Bybit signals a maturing industry norm where mutual aid and shared intelligence become critical components of risk mitigation. However, the suspension of withdrawals, even if temporary, tests user confidence and may invite closer scrutiny from regulators concerned about market stability and consumer protection. The discrepancy between initial on-chain estimates and final figures also serves as a cautionary note for analysts and investors relying solely on public blockchain data during active incidents, emphasizing the need for transparent, real-time communication from exchange operators to maintain credibility during high-stakes security events.


