Bitget Crypto Heist Sparks Fears of North Korean Involvement
A devastating cyberattack has struck cryptocurrency exchange Bitget, with hackers making off with a staggering $351.6 million in digital assets. What’s more worrying is that the methods used by these attackers bear a striking resemblance to those employed by notorious North Korean threat groups.
According to Bitget CEO Gracy Chen, the attack on September 24 was carried out using techniques consistent with known patterns of North Korean hacker organizations. While Chen did not directly attribute the heist to a specific group, her statement has sparked concerns about the involvement of state-sponsored hackers from the reclusive nation. The company’s security systems did catch the unauthorized transfers in real-time, but the attackers managed to exploit a critical backend system in Bitget’s wallet infrastructure to get fraudulent transfers approved.
The stolen funds include a variety of cryptocurrencies such as Ethereum (ETH), Ripple (XRP), Binance Coin (BNB), Avalanche (AVAX), Tether (USDT), and USD Coin (USDC). XRP accounts for the largest loss on a single blockchain. Chen revealed that some blockchain foundations have already frozen wallet addresses linked to the attacker, which should help mitigate further losses.
Bitget has not yet determined how the attackers gained access to its systems, but it’s clear that the exchange’s security measures were compromised. The company has assured users that private keys were not compromised during the attack, and its self-custodial wallet Bitget Wallet was not affected as it operates on separate infrastructure.
This incident is not an isolated case of North Korean state-sponsored hacking. In recent years, these groups have stolen billions of dollars’ worth of cryptocurrency from various exchanges. The FBI has previously blamed North Korea for a massive heist in February 2025, which saw $1.5 billion stolen from Bybit.
The investigation into the Bitget attack is ongoing, with Mandiant and blockchain security firm SlowMist assisting the exchange. This incident serves as a stark reminder of the importance of robust cybersecurity measures in the cryptocurrency space. As more sophisticated attacks continue to plague the industry, it’s essential for exchanges and users alike to remain vigilant and take steps to protect themselves from these threats.
One key takeaway from this incident is that users should be aware of the risks associated with centralized exchanges. While Bitget’s security systems caught the attack in real-time, the fact remains that a critical vulnerability was exploited by the attackers. As we move forward, it’s crucial for the industry to prioritize transparency and security measures to prevent such incidents from happening again. By staying informed about emerging threats and best practices, users can protect themselves and their assets from falling victim to these types of attacks.
Source: SecurityWeek — 2026-09-25