News

Bitget Suspects North Korean Hackers in $351.6M Security Breach

Bitget suspects North Korean hackers may have carried out a $351.6 million security breach. Withdrawals remain suspended. Investigators are examining the attack while the exchange says customer balances remain intact.

Written By : Yusuf Islam
Reviewed By : Pranchal Srivastava

Bitget suspects North Korean hackers may be behind a security breach involving about $351.6 million in digital assets. The crypto exchange has suspended withdrawals while investigators examine the intrusion. CEO Gracy Chen said preliminary evidence includes VPN-linked internet addresses associated with a North Korean hacking group. Bitget says customer balances remain accurate, while deposits and trading continue.

The exchange detected unauthorized wallet transfers Thursday afternoon stateside. According to Chen, the incident involved 19 transfers from parts of Bitget's hot and warm wallet systems. Its cold wallets remained secure.

Earlier blockchain estimates placed the outflows near $183 million. Bitget later said those estimates missed activity across several affected networks, bringing its reported loss to about $351.6 million.

Bitget Traces Breach to Critical Wallet Backend System

Bitget's investigation found that the attacker entered a critical backend wallet system. The intruder then spoofed transfer information and triggered the exchange's authorization-signing process, according to Chen.

The attack affected ether, XRP, USDT, USDC, Avalanche and BNB. Transfers occurred across Ethereum, XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum. Bitget says its security team has contained the breach and stopped additional unauthorized transfers.

Chen also ruled out a private key compromise. Investigators continue examining exactly how the attacker gained initial access to the backend infrastructure. Bitget has not disclosed a confirmed technical root cause.

What will Bitget's promised incident report reveal about the exact weakness that allowed an attacker to trigger its authorization process?

Withdrawals Remain Frozen as Bitget Repairs Systems

Bitget continues to block withdrawals while technical teams repair and strengthen the affected infrastructure. At the same time, deposits, spot trading and futures trading continue normally, according to the exchange.

Chen said withdrawals could return within hours or days, although she declined to provide a firm reopening time. She added during an X broadcast that the disruption “shouldn't take weeks.” Bitget's official notice gives no specific date.

Therefore, the reopening timeline depends on the outcome of the security review. Bloomberg reported that Chen said Bitget would publish a full incident report within 24 hours of the disclosure. The report is expected to cover the root cause and corrective measures.

Bitget also says customer account balances remain accurate despite the theft. Its User Protection Fund holds more than $464 million, which exceeds the estimated $351.6 million loss. The company says the fund can cover the incident in full.

North Korea Link Remains Preliminary as Investigation Continues

Bitget has not formally attributed the breach to North Korea. Chen said investigators found VPN-related IP addresses previously connected to a North Korean hacking group. She also said the attack pattern resembled earlier DPRK-linked operations.

Chen described insider involvement as unlikely based on the investigation so far. Independent researchers also observed similarities in the attackers' rapid conversion of stablecoins into ETH. Still, transaction behavior alone cannot establish who carried out an attack.

The suspected connection draws attention because North Korean state-linked groups have repeatedly targeted cryptocurrency infrastructure. The FBI formally blamed DPRK-linked TraderTraitor actors for Bybit's $1.5 billion theft in February 2025.

Read More: SpaceX Share Shortfall Forces Binance, Bybit and Bitget to Refund Users

That attack became the largest publicly disclosed cryptocurrency theft. It also showed how attackers could compromise infrastructure surrounding institutional wallet systems. Bitget has not reached the same level of attribution in its investigation.

Bybit CEO Ben Zhou said his team was ready to assist Bitget. Bitget had supported Bybit following the February 2025 attack. Zhou also said Bybit was updating its LazarusBounty platform to help trace the stolen assets.

For now, withdrawals remain unavailable until Bitget completes its technical review. The exchange says the attack no longer threatens further outflows, while investigators continue examining access methods, wallet infrastructure and possible links to DPRK-associated hackers.

Conclusion

Bitget says it contained the $351.6 million breach, protected cold wallets and maintained accurate customer balances. Withdrawals remain suspended while investigators determine the entry method and examine a possible North Korean connection. Users must rely on official Bitget updates for the withdrawal reopening timeline and incident report.

Join our WhatsApp Channel to get the latest news, exclusives and videos on WhatsApp

Crypto News Today: Bitcoin Inflow, KelpDAO Sues LayerZero, Bitget Gets Hacked

EU Regulators Put Quantum Risk on Crypto Custody & Bank Agenda

Jumper to Launch JUMP Token Sale on Legion as it Spins Out to Build the Super-App for Onchain Finance

What is Ethereum’s Glamsterdam Upgrade?

XRP and XLM Pull Back as ETF Demand and Stellar Adoption Grow