The cryptocurrency exchange Bitget is pointing toward North Korean operatives as the likely culprits behind a massive security breach that drained approximately 352 million dollars in digital assets. Speaking during a livestream on X, Bitget CEO Gracy Chen explained that preliminary investigations have uncovered internet protocol addresses tied to VPN services frequently utilized by known North Korean hacking groups. She noted that the overall patterns of the heist mirror previous state-sponsored operations, although technicians are still working to pinpoint the exact method used to penetrate the company’s systems.
The attack unfolded on Thursday afternoon when unauthorized transfers were detected across nineteen different wallets within the platform’s hot and warm wallet infrastructure. While cold storage remained untouched, the intruders managed to breach a critical backend system to spoof transfer data and trigger authorization signatures. This allowed them to siphon off various assets including Ether, XRP, USDT, USDC, Avalanche, and BNB across multiple blockchain networks. Early external estimates placed the losses lower at around 183 million dollars, but Bitget clarified that those figures failed to account for activity across every affected chain.
In response to the crisis, Bitget has temporarily suspended withdrawals while engineers work to repair and fortify their defenses, though trading and deposits remain operational. Chen emphasized that private keys were not compromised and expressed confidence that withdrawal services would resume within hours or days rather than weeks. To reassure anxious users, the company stated that all customer balances remain accurate and that the total loss is completely covered by its internal User Protection Fund, which currently holds over 464 million dollars.
Support for Bitget has already arrived from industry peers who understand the volatility of cyber warfare in the crypto space. Bybit CEO Ben Zhou announced that his team is standing by to assist their counterparts in tracing the stolen funds using an updated version of their LazarusBounty platform. The gesture follows a reciprocal relationship between the two firms, as Bitget provided similar aid after Bybit suffered a staggering 1.5 billion dollar hack back in February 2025.





