Bitget Points to North Korean Hackers

Cryptocurrency exchange Bitget says a $351.6 million security breach that affected some of its wallets is likely linked to a North Korean hacking group.

Bitget CEO Gracy Chen disclosed the suspected connection during a live question-and-answer session following the attack, saying investigators had identified IP addresses whose VPN choices matched those associated with a North Korean group.

Chen said the pattern also resembled techniques seen in previous attacks attributed to North Korean hackers. However, the attribution remains preliminary and has not been independently confirmed.

The incident was detected on September 24, when Bitget's security systems identified unauthorised transfers from some of its hot wallets.

The exchange subsequently suspended withdrawals while keeping deposits and trading operational.

$351.6 Million in Assets Affected

Bitget said approximately $351.6 million in assets were affected by the incident.

The exchange's security notice said the unauthorised transfers were detected at 18:31 UTC on September 24. Emergency response procedures were activated within minutes.

The breach affected part of Bitget's hot and warm wallet infrastructure, while the company's cold wallets remained secure.

On-chain tracking produced slightly different estimates depending on the assets' market values at the time of calculation. Lookonchain estimated the value at about $356.8 million, while Bitget's official estimate remains approximately $351.6 million.

Among the assets identified in the stolen funds were XRP, Ethereum, USDT, USDC, BNB, Avalanche and other cryptocurrencies.

XRP represented the largest portion in one on-chain analysis, with about 102.93 million XRP valued at approximately $157.48 million at the time of the report. Around 31,890 ETH, worth approximately $85.75 million, was also identified.

Private Keys Were Not Leaked, Bitget Says

One significant finding from Bitget's preliminary investigation is that the incident does not appear to have resulted from a private-key leak.

According to the exchange, attackers compromised part of the backend infrastructure supporting its wallet operations and were able to initiate unauthorised transfers.

The investigation is still examining exactly how the attackers gained access to the affected systems.

Bitget's preliminary findings indicate that the fraudulent transactions reached the normal approval and signing stage rather than requiring the attackers to obtain the exchange's private keys directly.

The distinction is important because it suggests that the security incident may have involved manipulation of the systems controlling authorised transactions rather than a straightforward theft of cryptographic keys.

Bitget said a full technical investigation is continuing with outside security specialists and law-enforcement authorities.

Why Bitget Suspects North Korea

Chen's comments about North Korea are based primarily on preliminary technical indicators.

She said investigators identified IP addresses associated with VPN services that matched choices previously linked to a North Korean hacking group.

The behaviour also reportedly resembled patterns observed in earlier attacks attributed to North Korean cyber operations.

However, Bitget has not presented the attribution as a final conclusion.

The company's initial security notice specifically said it would not speculate about the attack vector while the investigation was ongoing.

That distinction is important because identifying similarities between infrastructure or attack patterns does not, by itself, conclusively establish who carried out an intrusion.

North Korea Has Been Linked to Major Crypto Thefts

The suspected connection has drawn attention because North Korean hacking groups have previously been linked to some of the cryptocurrency industry's largest thefts.

The FBI attributed the approximately $1.5 billion Bybit hack in February 2025 to North Korea. Researchers and authorities have also linked North Korean cyber operations to billions of dollars in cryptocurrency theft over recent years.

North Korean-linked groups have repeatedly targeted cryptocurrency businesses because stolen digital assets can potentially be moved across multiple blockchain networks and converted into other forms of value.

The Bitget investigation will therefore be closely watched by blockchain-security researchers and international authorities.

Bitget Suspends Withdrawals

Following the attack, Bitget temporarily suspended withdrawals as a security precaution.

Deposits and trading continued to operate, while the exchange reviewed its infrastructure and investigated the abnormal transfers.

Bitget said customer account balances remained accurate and that its User Protection Fund contained more than $464 million, enough to cover the exchange's estimated loss.

The company also said the affected funds fall within the coverage of the protection fund.

The exchange has notified law-enforcement agencies and blockchain-security firms about the incident.

Cold Wallets Remain Secure

Bitget operates a multi-layer wallet structure separating hot, warm and cold storage.

The exchange said the incident was limited to portions of its hot and warm wallet infrastructure and that cold wallets were not breached.

That separation is significant because cold wallets generally provide an additional layer of protection by keeping assets away from systems that are continuously connected to online services.

The incident nevertheless demonstrates that a compromise involving operational infrastructure can potentially result in substantial losses even without a direct private-key theft.

Investigation Continues

Bitget said it plans to publish a full incident report covering the root cause and corrective measures.

For now, the company has characterised the North Korean connection as a preliminary finding rather than a definitive attribution.

The exchange's immediate priorities are securing the affected infrastructure, monitoring the stolen assets and determining when withdrawals can safely resume.

Blockchain investigators are also tracking the movement of the stolen cryptocurrencies across different networks and addresses.

The scale of the incident makes it one of the largest reported cryptocurrency thefts of 2026 so far. If the final loss remains around $351.6 million, the breach would represent a significant test of Bitget's security architecture and its ability to protect users following a major attack.

For customers, the exchange's statement that its protection fund exceeds the estimated loss provides information about its stated ability to absorb the incident. The longer-term consequences will depend on the findings of the investigation, the recovery of any stolen assets and the measures Bitget implements before fully restoring withdrawals.

Read Also: 22-Year-Old Malone Lam Pleads Guilty to $245 Million Bitcoin Theft