North Korean Hackers Linked to $388M Bitget Crypto Exchange Theft: CEO
Bitcoin Magazine North Korean Hackers Linked to $388M Bitget Crypto Exchange Theft: CEO Crypto exchange Bitget has released more details on Thursday’s hack. This post North Korean Hackers Linked to...
Hackers from North Korea targeted crypto exchange Bitget on Thursday, according to an update from the CEO, making away with close to $388 million in digital assets — more than originally reported.
Bitget CEO Gracy Chen said Friday that the higher figure “reflects a more complete accounting of transfers during the incident.” Chen had first reported that over $350 million had been moved.
Security firms first flagged unauthorized transactions from the Victoria, Seychelles-based exchange’s hot wallets on Thursday before the company announced it had frozen withdrawals.
Bitget is the sixth biggest crypto exchange, processing over $1 billion in trading volume per day, according to CoinGecko data.
“Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations,” Chen wrote on X on Friday.
She added: “Our goal is to complete a full recovery as soon as possible. We will announce the specific time window immediately upon confirmation.”
In a security update, the exchange said it identified the digital assets stolen, which mostly included ethereum, tron, and USDT stablecoin — and no bitcoin. But a stolen funds tracker does show that the attacker has over $28.8 million in the leading cryptocurrency.
Crypto stealing criminals — especially from North Korea — have become more sophisticated and faster since last year. Experts have said that the use of artificial intelligence tools is allowing cyber crooks to work more efficiently.
U.S. authorities have long alleged that hacking groups with ties to the North Korea’s government, such as Lazarus, steal from crypto exchanges.
Crypto security is in the limelight after a string of breaches this year have the community reeling. Just in July, hackers targeted a firmware bug in the popular bitcoin hardware wallet, Coldcard, to steal nearly $120 million in user funds.
And this month, purported white-hat hackers withdrew about 4,000 bitcoins — worth about $320 million at the time — from Blockstream’s Liquid sidechain’s federation wallet. They then returned 85% and demanded to keep the rest as ransom days later.
Asanat Analysis — Why it matters
A $388M theft attributed to North Korean threat actors represents a scale that rivals major historical exchange breaches (Mt. Gox, FTX collapse), signaling that state-sponsored groups remain the highest-impact vector for crypto infrastructure compromise. Attribution to North Korea—likely via forensic blockchain analysis and infrastructure fingerprinting—echoes patterns from Lazarus Group operations (Ronin bridge $625M in 2022), suggesting these actors have evolved beyond one-time exploits into systematic, recurring targeting of exchange hot wallets and bridge contracts.
For Bitget specifically, the incident tests market confidence in a mid-tier exchange at a time when regulatory scrutiny and custody standards have become competitive differentiators. The speed of public disclosure and attribution detail may preserve some user confidence, but operational questions remain: whether funds were in cold storage, the specific attack vector (social engineering, supply chain, zero-day), and whether insurance or recovery mechanisms exist. The timing—amid broader recovery narratives in 2026—could dampen sentiment toward centralized exchange risk.
Systemically, this reinforces why institutional crypto infrastructure increasingly migrates toward decentralized settlement, hardware custody, and multi-signature governance. State actors exploiting exchange vulnerabilities are economically rational given sanctions-evasion motivations; the lesson for the sector is that scale concentration at single points of custody remains asymmetrically attractive to well-resourced adversaries.