Bitget CEO Links $352 Million Hack to North Korean Hackers
Bitget CEO Gracy Chen has suggested that North Korean hackers might be behind the exchange's recent $351.6 million security breach. During a live Q&A session, Chen cited preliminary findings that linked specific IP addresses to VPN services commonly used by a group associated with the Democratic People’s Republic of Korea (DPRK).
Chen emphasized that the exchange does not believe the breach was an inside job, stating, "We’ve identified some IP addresses that match the VPN choices by a certain DPRK group." This assertion comes in the wake of a broader context in which North Korean hackers have been implicated in significant cryptocurrency thefts, including an estimated $2.02 billion in total, with the FBI attributing a notable $1.5 billion hack of the Bybit exchange to them.
The CEO noted that the patterns observed in this breach closely resemble those of previous attacks attributed to North Korean cybercriminals. She explained that the hackers managed to breach Bitget's systems and transfer funds directly, rather than forging user withdrawal requests or accessing the private keys of the exchange's cold and warm wallets.
Investigation into Compromised Systems Underway
Investigators are still working to ascertain which systems were compromised and how the attackers gained access to Bitget's infrastructure. Following the breach, the exchange reported unauthorized transfers affecting parts of its hot and warm wallet infrastructure, leading to a suspension of withdrawals.
Cleared for Release
During the Q&A, Chen also mentioned that some of the stolen funds had been recovered, although she did not disclose the specific amount. The exchange is collaborating with blockchain foundations and other partners to facilitate recovery efforts.
As the investigation unfolds, Bitget remains focused on understanding the full scope of the breach and ensuring the security of its platform. The incident highlights ongoing concerns regarding cybersecurity in the cryptocurrency sector, particularly in relation to state-sponsored hacking activities. The exchange's proactive approach in addressing the breach and working towards recovery may serve as a critical step in restoring user confidence and safeguarding assets in the future.