Bitget says North Korea likely behind $352M hack as withdrawals pause
Bitget says about $352 million was stolen in a hack
Bitget, a crypto exchange where people trade digital assets, says it lost roughly $352 million in a hack. The exchange's CEO, Gracy Chen, said in a livestream that the attack shows the signs of a North Korean operation.
Large withdrawals were first spotted from addresses labelled as Bitget hot and cold wallets the day before the report, which raised alarm among crypto users. Crypto investigator Specter Analyst linked the attack to Lazarus Group, a North Korean hacking collective. Chen later said the attack carried the marks of a North Korean operation.
Key facts about the attack
- About $352 million was taken, according to the exchange's CEO.
- The hack happened as Bitget marked its eighth birthday.
- Losses were at first expected to be much smaller.
- Withdrawals were temporarily paused.
What the CEO says about how the hack worked
Chen ruled out a compromise of a private key, the secret code that controls access to a wallet. She said the attackers breached the wallet services backend system, forged transfer details, and authorized their own signing processes.
She said Bitget's cold wallets stayed secure and that hot wallet and warm wallet layers were the target. That differs from earlier reports of withdrawals being seen from addresses labelled as both hot and cold wallets.
Frozen addresses and a separate Bitget wallet
Chen said several blockchains have frozen addresses tied to the hack. She also said the Bitget wallet, a product that is separate from the exchange, was not affected.
User funds and the protection fund
Chen said user funds are safe and that most of the loss is covered by Bitget's User Protection Fund, which she said holds more than $464 million.
What is confirmed and what is still a claim
Chen has confirmed the loss of roughly $352 million, the pause on withdrawals, the freezing of some addresses across chains, and the appointment of independent investigators Mandiant and SlowMist.
The exact method of the attack and who carried it out are not confirmed. Chen described signs of a North Korean operation, and an independent investigator made the Lazarus Group link. The attribution remains a claim rather than a confirmed fact.
What happens next
Bitget says it is working with Mandiant and SlowMist to fully determine what happened, and that withdrawals remain temporarily paused.