Bitget Suffers $351M Hack Possibly Linked to North Korean Attackers, CEO Says

By Nynu Jamal

Key highlights:

  • The Bitget hack may have been executed by North Korean hackers, stated CEO Gracy Chen
  • Hackers accessed a critical backend system and moved $351 million in assets
  • The CEO confirmed that the cold wallets were not compromised

Crypto exchange Bitget has suffered one of the largest security incidents recently. Hackers reportedly moved about $351.6 million in assets from the exchange’s wallets. As the company is now investigating the Bitget hack, CEO Gracy Chen hinted at the incident’s possible link to North Korean hackers.

Bitget suffers $351M crypto hack

Earlier today, Bitget CEO Gracy Chen confirmed on her X account that the crypto exchange was hit by a security incident on September 24. As she noted, hackers accessed the platform’s internal systems, with around $351.6 million stolen from the wallets.

On September 24, Bitget identified unauthorized transfers from some of its hot and warm wallets. While the team reported that more than $350 million has been moved from these wallets, Chen confirmed that the cold wallets were not affected. She noted:

“Cold wallets remain fully secure. Bitget operates a three-tier wallet architecture — the breach contained only a portion of the hot wallet and warm wallet layers.”

Some blockchain researchers had already identified the unusual activity on Bitget even before the exchange revealed the attack. According to initial reports, the hackers moved around $183 million in crypto. Initially, it appeared that the hackers stole ETH, BNB, AVAX, and USDT, but Arkham Intelligence analyst Emmett Gallic notes that the attackers also took off with $153M worth of XRP.

CEO points to possible North Korean link

Following the Bitget hack, the company has started investigating it. The team is actively trying to identify what happened. As Chen stated, the company confirmed that IP addresses used during the attack showed VPN usage patterns. This has sparked speculation about the involvement of North Korean hackers, as they usually use similar patterns.

However, it is worth noting that the attack does not appear to have involved the direct theft of the exchange’s wallet private keys. Chen stated that the attackers haven’t gained access to Bitget’s hot, warm, or cold wallets. Instead, the attackers might have breached Bitget’s internal systems and used them to steal the assets.

As of now, the North Korean link is not confirmed. Gracy Chen’s statement is based on the current findings, and they are not enough to confirm that North Korean hackers executed the Bitget hack.

Gracy Chen reveals more details on the hack 

In another subsequent X post, Gracy Chen revealed other details linked to the Bitget hack. She confirmed that the attacker gained access to a critical backend system connected to the exchange’s wallet infrastructure.

The attacker then used this compromised system to create fake transaction data. They also used it to trick Bitget’s authorization process into approving unauthorized transfers, allowing the attacker to move funds out of the system.

However, Chen clarified that the exchange’s private keys were not compromised, adding:

“Private key compromise has been ruled out — this excludes the more severe risk scenarios. Loss containment is confirmed. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation. A full technical report will follow once confirmed.”

Source:: Bitget Suffers $351M Hack Possibly Linked to North Korean Attackers, CEO Says