Skip to content
CRYPTO & DECENTRALIZED TECH

North Korea-Linked Hackers Target Bitget in Massive $388 Million Digital Asset Heist

Hackers widely believed to be operating out of North Korea targeted cryptocurrency exchange Bitget in a sophisticated cyberattack, making away with close to $388 million in digital assets. The revised figure represents a significant upward revision from the initial estimates reported in the immediate aftermath of the breach.

Bitget CEO Gracy Chen provided an update on Friday, stating that the higher total reflects a more comprehensive and complete accounting of all unauthorized transfers that occurred during the security incident. Initially, Chen had reported to the public and stakeholders that over $350 million had been surreptitiously moved out of the platform’s control.

The security breach first came to light on Thursday when independent blockchain security firms flagged suspicious, unauthorized transactions originating from the hot wallets of the Victoria, Seychelles-registered exchange. As the automated alerts and on-chain tracking tools highlighted the massive outflows, Bitget moved swiftly to mitigate further damage by announcing the immediate freezing of all user withdrawals, halting the bleeding while security teams scrambled to assess the extent of the compromise.

Bitget maintains a prominent position within the global digital asset ecosystem, ranking as the sixth-largest cryptocurrency exchange by trading volume. According to market data aggregator CoinGecko, the platform routinely processes over $1 billion in daily trading volume, underlining the immense scale and liquidity managed by the exchange on a day-to-day basis.

Addressing the public and the broader crypto community on Friday via a post on social media platform X, CEO Gracy Chen pointed the finger firmly at state-sponsored threat actors. She noted that an evaluation of IP behavior patterns and rigorous on-chain analysis revealed that the attack methodology employed in the incident bears a striking, highly consistent resemblance to the known tactics, techniques, and procedures of North Korean hacker organizations.

Chen further emphasized the company’s absolute priority following the breach, stating that their primary goal is to complete a full recovery of the stolen funds as rapidly and securely as possible. She assured users and investors that the exchange will announce a specific time window for updates immediately upon internal confirmation and validation of their recovery milestones.

In a subsequent detailed security update released by the exchange, Bitget officials reported that they have successfully identified the specific digital assets that were stolen during the raid. The stolen reserves predominantly consisted of Ethereum, Tron, and the USDT stablecoin, with the exchange noting an initial absence of Bitcoin in the primary asset breakdown. However, independent on-chain analysis and data provided by specialized stolen funds trackers reveal a slightly more nuanced picture, showing that the malicious actors are currently holding over $28.8 million in the world’s leading cryptocurrency as part of their illicit haul.

The brazen attack on Bitget highlights an alarming trend that has intensified over the past year. Cybersecurity experts and intelligence analysts have repeatedly warned that cybercriminals—particularly those operating under the umbrella or direction of North Korean state-sponsored initiatives—have grown increasingly sophisticated, highly coordinated, and operationally faster. Industry specialists have pointed out that the modern adoption and integration of advanced artificial intelligence tools by these cyber crooks are enabling them to execute complex, multi-layered attacks with unprecedented efficiency and precision.

For years, law enforcement and regulatory authorities in the United States and other allied nations have maintained that elite hacking syndicates with deep ties to the North Korean government, such as the notorious Lazarus Group, systematically target international cryptocurrency exchanges and financial institutions. These operations are widely believed by intelligence agencies to serve as a primary mechanism for generating illicit revenue to fund the isolated regime’s state programs.

The devastating breach at Bitget has once again thrust the broader issue of cryptocurrency security into the intense global limelight. The incident comes on the heels of a relentless string of high-profile security breaches throughout the year that have left the digital asset community deeply unsettled and demanding more robust protective measures from custodians and platforms alike.

Just in the month of July, malicious actors successfully targeted a critical firmware vulnerability in the popular Bitcoin hardware wallet Coldcard. That exploit allowed the attackers to compromise devices and siphon off nearly $120 million in user funds, demonstrating that even cold storage methodologies are vulnerable when underlying hardware or supply chain vectors are compromised.

Compounding the atmosphere of unease, another dramatic security event unfolded earlier this month involving Blockstream’s Liquid sidechain. In that incident, purported white-hat hackers managed to withdraw approximately 4,000 bitcoins—worth an estimated $320 million at the time of the transaction—directly from the federation wallet of the Liquid network. Following intense on-chain negotiations and public communication, the ethical hackers ultimately returned roughly 85% of the stolen funds while demanding to retain the remaining portion as a bounty days later.

As investigations into the Bitget breach continue, security researchers and blockchain analysts are monitoring the movement of the stolen $388 million across various decentralized protocols and mixing services. Meanwhile, Bitget leadership remains under pressure to restore full functionality, enhance its security architecture, and provide clarity to its global user base regarding asset safety and reimbursement plans.

Leave a Reply

Your email address will not be published. Required fields are marked *