Updated
Updated · CNBC · Sep 25
Bitget Suspects North Korea in $351.6 Million Hack, Freezes Withdrawals
Updated
Updated · CNBC · Sep 25

Bitget Suspects North Korea in $351.6 Million Hack, Freezes Withdrawals

3 articles · Updated · CNBC · Sep 25

Summary

  • $351.6 million in digital assets was siphoned from Bitget in 19 unauthorized transfers on Thursday, hitting hot and warm wallets across five blockchain networks while cold wallets stayed secure.
  • IP addresses tied to VPN services previously used by a North Korean hacking group and attack patterns resembling earlier operations led Bitget to suspect Pyongyang-linked hackers, though the exact intrusion method is still under investigation.
  • Bitget said the attacker breached a critical backend wallet system, spoofed transfer information and triggered its authorization-signing process; it has ruled out a private-key compromise and says the breach is contained.
  • Withdrawals remain suspended as systems are repaired, but deposits and trading continue; CEO Gracy Chen said withdrawals could resume within hours or days, not weeks.
  • Customer balances remain intact, Bitget said, with losses covered by a user protection fund holding more than $464 million, while Bybit said it would help trace the stolen funds through its LazarusBounty platform.

Insights

If private keys were never compromised, how did hackers successfully trick Bitget's backend into authorizing a massive $351 million drain?
Could blaming sophisticated North Korean hacking groups be a convenient smokescreen for an inside job at a major crypto exchange?
How can the crypto industry survive when state-sponsored attackers exploit traditional backend flaws rather than breaking blockchain cryptography?