Bitget Attributes $352 Million Hot Wallet Heist to Suspected North Korean Cyber Syndicate as Protection Fund Absorbs Losses

SINGAPORE — Global cryptocurrency exchange Bitget has suffered a major security breach resulting in the unauthorized transfer of digital assets valued at approximately $351.6 million, with the platform attributing the incident to suspected North Korean state sponsored cyber threat actors following preliminary forensic assessments.

The breach was detected when automated internal monitoring systems flagged irregular outbound transfers originating from a targeted group of hot and warm wallets. In an official communication, Bitget Chief Executive Officer Gracy Chen confirmed that unauthorized transactions compromised assets across seven major distributed networks, including the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain, and Base networks. The single largest individual network loss was sustained on the XRP Ledger.

Technical disclosures indicate that attackers managed to breach an internal backend wallet service platform rather than obtaining raw custodial private keys. By compromising the backend coordination layer, the intruders spoofed transaction payloads to satisfy automated authorization and signing routines, facilitating rapid asset flight before anomalous volume alerts triggered emergency lockdowns. Bitget clarified that the vast majority of assets residing in cold storage were untouched and the independently managed Bitget Wallet architecture remained unaffected.

Bitget enacted an immediate suspension of customer withdrawals to permit end to end security reviews, while retaining active spot trading and deposit operations. Forensic teams from Google Cloud’s Mandiant and blockchain security firm SlowMist have been deployed alongside international law enforcement agencies to map funds, with several blockchain foundation partners successfully freezing flagged hacker addresses.

The exchange confirmed that verified customer account balances remain intact, with financial exposure backstopped by its User Protection Fund, which holds over $464 million primarily denominated in Bitcoin. The attack adds to a mounting tally of high volume cyber assaults attributed to North Korean hacking entities, highlighting systemic transaction layer vulnerabilities across centralized trading venues as institutional capital continues flowing into digital asset ecosystems.

Previous
Previous

e& UAE Unveils Sovereign Secure Website Hosting Platform Backed by 24/7 Dual NOC and SOC Oversight for Government and Enterprise

Next
Next

German Regulators and Law Enforcement Disconnect Thousands of Phone Lines in Sweeping ‘Operation Heracles’ Cyber Trading Crackdown