Bitget CEO Links $350 Million Hack to North Korean Group
Bitget, a prominent cryptocurrency exchange platform, faced a major security breach in September, which has been described by market analysts as one of the largest cryptocurrency hacks of the year. Following the incident, the exchange's CEO, Gracie Chen, revealed that the hack may be traced back to North Korea.
On September 24, Bitget detected unauthorized transfers from several of its hot wallets. Chen explained that the exchange traced IP addresses involved in the breach, which exhibited VPN activity patterns closely associated with a known group linked to North Korea. She characterized the connection to the Democratic People's Republic of Korea (DPRK) as "very likely."
Importantly, Chen noted that the attackers did not gain access to the private keys of any of Bitget's hot, warm, or cold wallets. Instead, they compromised the internal systems of the exchange to facilitate the transfer of funds directly.
To alleviate concerns among users, Bitget stated that its user protection fund, which exceeds $464 million, is sufficient to cover the losses incurred from the breach. The exchange reported unauthorized transfers totaling approximately $351 million, with significant outflows in various cryptocurrencies, including USDC, ETH, and USDT.
In a recent livestream update, Chen provided further details about the security incident, which lasted over three hours. The unauthorized transfers affected multiple assets, including ETH, XRP, BNB, AVAX, USDT, and USDC, across several networks such as Ethereum, the XRP Ledger, and BNB Smart Chain. Bitget confirmed that all of its on-chain cold wallets remained secure and unaffected by the breach.
Efforts to Recover Stolen Assets Underway
The exchange has reached out to the foundations of the affected blockchains, and some have already taken action to freeze the relevant hacker wallet addresses. Bitget is actively pursuing all available recovery options and will continue to provide updates as more information becomes available.
Analysis of IP behavior and on-chain data suggests that the methods used in the attack align closely with tactics employed by North Korean hacking groups. Bitget has reported the incident to the appropriate authorities and is cooperating with a global investigation.
Clearance Granted
The company emphasized that its decentralized Bitget Wallet operates independently of the exchange's infrastructure and remains completely unaffected. User assets held in the Bitget Wallet are secure.
Chen reiterated that the user protection fund exceeds $464 million and is held in publicly verifiable wallet addresses, ensuring transparency. Additionally, the company's proprietary assets surpass $1 billion, with user funds backed 1:1. The exchange aims to restore full access to withdrawals as quickly as possible and will announce a specific recovery timeline once confirmed.