Quick Summary
- Cryptocurrency exchange Bitget suffered a $351.6 million security breach through a compromised backend wallet system.
- No private keys were compromised, according to CEO Gracy Chen, avoiding the crypto industry’s most catastrophic breach scenario.
- Hackers manipulated transaction data, deceiving Bitget’s authorization protocols into validating fraudulent fund transfers.
- Forensic analysis reveals IP address patterns consistent with North Korean cybercriminal operations using VPN networks.
- The platform’s $464 million protection reserve fully covers losses, though withdrawal services remain suspended pending investigation.
Bitget, one of the world’s leading cryptocurrency trading platforms, experienced a devastating $351.6 million security breach during overnight operations. The exchange’s CEO, Gracy Chen, publicly acknowledged the incident through her official X account.
According to Chen, the breach did not compromise any private keys. These cryptographic credentials function as the ultimate security layer, essentially combining password and vault access for cryptocurrency holdings.
Rather than targeting these keys directly, the perpetrators infiltrated a backend infrastructure component connected to Bitget’s wallet management system. This access enabled them to manipulate transaction records and authorization requests.
The Attack Methodology Explained
Chen described the incident using an analogy of fraudulent banking documents. She explained it was similar to criminals successfully submitting counterfeit withdrawal forms through legitimate bank channels, while the actual vault security remained intact.
The attackers fabricated documentation that appeared legitimate within Bitget’s systems. This fraudulent paperwork successfully navigated the exchange’s standard verification protocols, leading the automated systems to treat these requests as authorized transactions.
Bitget’s security monitoring first identified suspicious activity at 18:31 UTC on September 24. The alert system detected unauthorized fund movements originating from the platform’s hot wallet infrastructure—internet-connected storage used for active trading operations and user withdrawals.
Beyond hot wallets, the compromise extended to Bitget’s warm wallet tier. This intermediate storage layer bridges hot wallets and offline reserves, automatically replenishing operational balances when needed.
Chen emphasized that cold storage wallets, maintained completely offline, remained untouched throughout the incident. She described these offline reserves as “fully secure” and unaffected by the breach.
Once detected, Bitget immediately halted all outgoing fund transfers. Chen assured users that no additional unauthorized movements are currently possible under existing security protocols.
Attribution and Threat Analysis
Preliminary forensic investigation points toward North Korean state-sponsored actors, according to Chen. Security analysts identified IP addresses matching VPN infrastructure previously associated with established North Korean hacking operations.
The attack signature and methodology align with historical patterns from North Korean cyber operations. Bitget’s internal investigation has ruled out the possibility of insider involvement.
Independent blockchain analyst Specter published findings on X connecting the stolen cryptocurrency to wallet addresses implicated in previous exploits. The analysis links these addresses to an entity identified as “AFX EXPLOITER” from a prior $24 million security breach.
North Korean hacking groups have allegedly stolen approximately $2.02 billion in cryptocurrency throughout 2025. This figure includes the massive $1.5 billion Bybit breach, which U.S. federal investigators officially attributed to North Korean operations.
Bitget has not issued definitive attribution regarding the attackers’ identity. Chen stated the investigation remains ongoing with multiple security partners involved.
Recovery Process and User Impact
Bitget maintains a User Protection Fund exceeding $464 million in total reserves. Chen confirmed this insurance mechanism provides complete coverage for the stolen amount.
“User funds are safe,” Chen stated. “Your account balances are accurate and your assets are protected.”
The exchange currently permits deposit and trading activities to continue normally. However, withdrawal functionality remains disabled during the comprehensive security assessment.
Chen declined to specify when withdrawal services will resume operations. She indicated multiple technical teams are conducting parallel remediation efforts across affected systems.
“We will announce a timeline as soon as one is confirmed,” she explained. “We will not commit to a window we cannot guarantee.”
In a live question-and-answer session conducted on X, Chen revealed that recovery efforts have successfully retrieved a portion of the stolen assets. She did not disclose specific amounts recovered.
Bitget is coordinating with various blockchain foundations and industry partners on asset recovery initiatives. The platform plans to publish a comprehensive technical analysis once the investigation concludes.
The post $352 Million Bitget Breach: North Korean Hackers Suspected Again appeared first on Blockonomi.

1 hour ago
23









English (US) ·