Bitget CEO suspects North Korea behind $352M hack, citing IP clues

Bitget CEO Gracy Chen stated that North Korean hackers may be responsible for the recent $351.6 million security breach at the exchange. During a live Q&A session, she revealed that preliminary investigations uncovered IP addresses linked to VPN services commonly used by a North Korean group. The exchange is still assessing which systems were compromised and is collaborating with partners to recover stolen funds.
Suspicions Rise Against North Korea After Massive Breach
Bitget CEO Gracy Chen addressed the $351.6 million hack during a live Q&A on X, pointing out that the attack bore striking similarities to previous incidents attributed to North Korean hackers. Security investigators identified certain IP addresses linked to VPN services commonly used by a Democratic People’s Republic of Korea (DPRK) group. Chen dismissed the possibility of an inside job within the exchange.
Attack Methodology and Details of the Breach
Chen explained that the hackers directly accessed Bitget’s systems and transferred funds without fabricating user withdrawal requests. The attackers did not gain access to the private keys of the cold, hot, or warm wallets. Investigations are ongoing to determine which specific systems were compromised and the exact entry points used by the attackers.
Historical Context and Scale of DPRK-Linked Crypto Thefts
The CEO referred to estimates indicating North Korean hackers stole approximately $2.02 billion in cryptocurrency in 2025 alone. A notable incident includes the around $1.5 billion hack of the Bybit exchange, which the FBI attributed to DPRK-backed operations. The pattern observed in Bitget’s hack strongly resembles those previous North Korean campaigns.
Bitget’s Response and Recovery Efforts
The breach occurred on Thursday, involving unauthorized transfers from portions of Bitget’s hot and warm wallet infrastructure, leading the exchange to suspend all withdrawals. Chen revealed that some stolen funds have been recovered so far but did not disclose specific amounts. The exchange is collaborating with blockchain foundations and various partners to aid in fund recovery and remedial measures.
Why it matters
This news is significant for the cryptocurrency industry as it highlights the ongoing involvement of state-sponsored hackers, particularly from North Korea, in major cyberattacks targeting crypto exchanges. The link underscores that despite enhanced security measures, attackers continue to employ sophisticated tactics to steal large sums of digital assets. Furthermore, the public disclosure of details and collaboration with blockchain partners exhibit exchanges’ commitment to damage control and transparency, which are crucial for user trust and regulatory confidence in the digital financial ecosystem.
Prepared from the source material with AI-assisted editing and checked against the supplied facts.
Open original source ↗