Bitget CEO suspects North Korea behind $352M hack, citing IP clues
Source Entity
Cointelegraph by Felix Ng

Cryptocurrency exchange Bitget has suffered a massive security breach resulting in the theft of approximately $388 million in assets. North Korean hackers are suspected of orchestrating the attack, which targeted the exchange's hot wallets and forced a temporary suspension of withdrawals.
The Bitget Breach: A Massive Crypto Heist
The cryptocurrency sector is once again grappling with the reality of large-scale cyber vulnerabilities following a major security breach at the exchange Bitget. Initially reported as a $351 million theft, subsequent analysis of on-chain data regarding assets on Zcash and TRON has revised the total impact to approximately $388 million. This incident stands as the largest digital currency heist of the year, underscoring the persistent threat posed by sophisticated cyber actors targeting hot wallet infrastructure.
The Anatomy of the Attack
According to official statements from Bitget, the breach occurred when unauthorized actors gained access to a specific subset of the exchange’s hot and warm wallet layers. These wallets, which are connected to the internet to facilitate active trading, represent a primary attack vector due to their accessibility. While the company confirmed that its cold wallets—which are stored offline and are inherently more secure—remained unaffected, the sheer scale of the unauthorized transfers forced the immediate suspension of withdrawals to prevent further losses.
Attribution and Strategic Implications
Security experts and investigators have pointed toward North Korean hackers as the primary suspects behind this operation. This follows a long-standing pattern of state-sponsored cyber activity linked to North Korea, where digital currency theft is often utilized to bypass international sanctions and fund state operations. The complexity and scale of this heist suggest a highly coordinated effort, marking a significant escalation in the ongoing conflict between centralized crypto exchanges and well-funded, persistent threat actors.
Exchange Response and User Protection
In the wake of the breach, Bitget CEO Gracy Chen has emphasized that while withdrawals were paused, core trading functionality and user deposit accounts remain stable. The exchange has moved to implement emergency response procedures, including the launch of a bounty program designed to incentivize the freezing or recovery of the illicitly transferred assets. With a reported $464 million in its user protection fund, the exchange is positioning itself to mitigate the impact of the theft on its customer base.
Broader Industry Trends
This event is not an isolated incident but rather the latest in a series of high-profile hacks that have plagued the cryptocurrency ecosystem throughout the year. It notably eclipses a $340 million hack that occurred in September. The industry is currently facing a critical juncture regarding security protocols; as exchanges grow in size and liquidity, they become increasingly attractive targets for state-sponsored entities. The reliance on hot wallets, while necessary for liquidity, remains the 'Achilles' heel' of the sector, necessitating a fundamental shift in how digital assets are secured and managed in real-time.
Future Outlook
As investigations continue, the focus will likely shift toward stricter regulatory oversight and improved on-chain tracing capabilities. The fact that the initial theft estimate had to be revised upward by $35 million highlights the difficulty of tracking assets across multiple blockchains like TRON and Zcash. Going forward, exchanges will face mounting pressure to demonstrate transparency and enhance their security architecture to regain user trust. The outcome of Bitget's recovery efforts will likely serve as a benchmark for how exchanges handle such crises in the future.