Bitget CEO says North Korean hackers may be behind $351.6M breach

Bitget CEO says North Korean hackers may be behind $351.6M breach

Bitget CEO points to North Korean VPN clues after $351.6M breach

Bitget CEO Gracy Chen said North Korean hackers may be behind a security breach at the crypto exchange worth $351.6 million. She pointed to early findings that link IP addresses to VPN services used by a North Korean group.

An IP address is a number that identifies a device online. A VPN is a tool that hides a user's real location by routing traffic through another server. Chen gave the details during a live question-and-answer session on X after the incident.

An independent onchain researcher, Specter, also said the theft may be tied to a North Korea-linked hacking collective, based on tracing some of the stolen funds.

Key details from the exchange and the researcher

  • Chen said some IP addresses matched the VPN choices of "a certain DPRK group," referring to the Democratic People's Republic of Korea, or North Korea.
  • She said the exchange does not believe the breach was an inside job.
  • Chen said the pattern looked very much like earlier North Korean attacks.
  • Specter said some stolen XRP was traced to an Ethereum address that received 68,808 USDT from a wallet. That same wallet had once sent Ethereum to an address labeled "AFX EXPLOITER."
  • AFX, which was hacked for $24 million in July, said in its own review that it suspected TraderTraitor, a group linked to North Korea.

What Bitget says about how the hack worked

Chen said hackers breached a backend system of the wallet service and used it to forge transfer information. She said the attackers invoked the authorization signing process.

She said they did not forge user withdrawal requests and did not obtain the exchange's private keys for its cold wallet or any hot or warm wallet. In crypto, a wallet holds the keys that control funds, and a private key is the secret code that allows those funds to be moved. Cold wallets are kept offline, while hot and warm wallets are connected to the internet in varying degrees.

Bitget said on Thursday that unauthorized transfers affected parts of its hot and warm wallet infrastructure. Withdrawals were still suspended when the article was published.

Recovery efforts and open questions

Chen said some of the stolen funds had been recovered, but she did not say how much. She said the exchange is working with blockchain foundations and other partners on recovery. A blockchain is a shared record of transactions that many computers maintain.

Chen said investigators were still working out which systems were compromised and how the attackers got in.

What is confirmed and what is not

Confirmed: Bitget reported unauthorized transfers affecting parts of its hot and warm wallet infrastructure, and withdrawals were suspended. Chen described the IP findings, the suspected method of the attack, and the partial recovery of funds in public remarks. Specter published the wallet tracing. AFX previously said it suspected a North Korea-linked group in its own case.

Not confirmed: No official attribution has been announced by authorities. Chen's view that North Korea may be responsible is based on a preliminary investigation and is a suspicion, not a confirmed finding. Specter's tracing is an independent allegation. The exact amount recovered was not disclosed. It is not yet clear which systems were breached or how the attackers gained access.

Why the North Korea link draws attention

Chen's remarks were compared with previous cases. According to the source material, North Korean hackers were linked to an estimated $2.02 billion in crypto theft in 2025. That included the roughly $1.5 billion Bybit exchange hack, which the FBI attributed to North Korea.

Sources

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!