Cryptocurrency exchange Bitget has suffered a major security breach that resulted in approximately $351.6 million in unauthorized transfers, with early findings raising suspicions that North Korean hackers may have been involved.

 

 

Bitget detected the suspicious activity at 18:31 UTC on September 24 after funds began moving from part of its wallet infrastructure. The company activated its emergency response procedures within minutes and temporarily suspended withdrawals while investigators worked to determine how the attackers gained access.

The breach was limited to portions of Bitget’s hot and warm wallet systems, according to the exchange. Its offline cold wallets remained secure, and Bitget says customer account balances continue to accurately reflect their holdings. Deposits and regular trading remained available following the incident, although some on-chain services were temporarily affected by the security review.

Bitget CEO Gracy Chen said investigators have ruled out the theft of private keys, suggesting the attackers found another way to authorize transfers from the company’s infrastructure. Preliminary findings reportedly point toward a compromise involving a backend wallet system, but the precise entry point and attack method remain under investigation.

Attention has also turned to North Korea. Chen said investigators identified IP addresses associated with VPN services previously used by a North Korean hacking group and noted similarities with earlier attacks. She described North Korean involvement as very likely but did not identify a specific group.

Independent blockchain researchers have attempted to connect the stolen cryptocurrency with funds associated with previous attacks attributed to North Korean operators. However, these findings do not yet provide definitive attribution, and Bitget has not officially blamed the Lazarus Group or another named organization.

The exchange has flagged addresses receiving the stolen cryptocurrency and contacted law enforcement agencies and blockchain security companies. Some of the assets were quickly moved or exchanged across different blockchain networks, complicating efforts to freeze and recover the funds.

Bitget maintains a User Protection Fund worth more than $464 million, which the company says is sufficient to cover the estimated loss. It has assured customers that their assets remain protected despite the scale of the theft.

Withdrawals remained suspended while the security review continued. Bitget has promised a detailed incident report covering the root cause and corrective measures, which should provide a clearer picture of how attackers were able to move hundreds of millions of dollars without obtaining the exchange’s private keys.

Leave a Reply