Bitget CEO suspects North Korea behind $352M hack, cites IP clues

Editorial illustration: A large magnifying glass enlarges branching metallic network nodes, several glowing amber. A cracked shield stands on the left, and an interrupted dotted trail leads toward a North Korean flag on the right.

In brief

  • Bitget suffered $351.6M unauthorized transfers from hot and warm wallet infrastructure Thursday
  • CEO Gracy Chen identified IP addresses matching North Korean hacking group VPN choices
  • Investigators found similarities to previous DPRK attacks; cold wallet keys remained secure
  • Bitget suspended withdrawals, recovered partial funds; entry point still under investigation
  • North Korean hackers attributed to $2.02B crypto theft in 2025

Attack Pattern and Attribution

Bitget CEO Gracy Chen said investigators flagged similarities with previous North Korean attacks. "The pattern looks very much like what the North Korean team did before," Chen said in a statement.

The breach wasn't an inside job, Chen said. Hackers breached Bitget's systems and transferred funds directly rather than forging user withdrawal requests. Critically, attackers did not obtain the exchange's private keys of cold, hot, or warm wallets — a significant constraint on the damage scope.

Recovery and Context

Bitget suspended withdrawals following the breach. The exchange said some stolen funds had been recovered, without specifying an amount. Bitget is working with blockchain foundations and other partners on recovery efforts.

North Korean hackers were linked to an estimated $2.02 billion in crypto theft in 2025. The FBI previously attributed the roughly $1.5 billion Bybit exchange hack to North Korea, establishing a pattern of sophisticated targeting of centralized exchanges.

Investigators are still determining which systems were compromised and how attackers gained access. The ongoing investigation will be critical to understanding whether this represents a new exploit vector or a variation of known DPRK techniques.