Cryptocurrency exchange Bitget suspects North Korean hackers may be behind a security breach that affected approximately $351.6 million in digital assets, citing preliminary evidence from an ongoing investigation.
Bitget CEO Gracy Chen said investigators had identified an Internet protocol address linked to a VPN service previously used by a North Korean hacker group. The pattern of attacks was also similar to earlier operations attributed to this country, she said on an X livestream earlier today.
Chen said the specific intrusion method used to break into Bitget’s systems is still under technical investigation.
Chen said BitGet detected fraudulent transfers from some wallets in the United States on Thursday afternoon, including 19 transfers from some of its hot and warm wallet infrastructure, but cold wallets remained secure.
Affected assets include Ethereum, XRP Ledger, Avalanche, BNB Smart Chain, Ether across the Arbitrum network, XRP, USDT, USDC, Avalanche, and BNB. Previous on-chain estimates put the breach at around $183 million, but Bitget said these analyzes do not capture activity on all affected blockchains.
The exchange’s security team discovered that the attackers had compromised a critical backend wallet system and used it to spoof transfer information and trigger Bitget’s authorization signing process. Chen said the breach was stopped and further unauthorized access was prevented.
“Private key compromise has been eliminated,” she said.
Withdrawals remain suspended while our technical team repairs and hardens the affected systems, but deposits and transactions will proceed as normal.
Chen declined to commit to a specific timeline, but said on X’s broadcast hours after the attack that withdrawals could return within hours or days, but “it shouldn’t take weeks.”
The company insists that customer balances are accurate and that any losses will be fully covered by the User Protection Fund, which holds more than $464 million.
Bybit CEO Ben Zhou said his team is on standby to assist Bitget, which supported Bybit following the $1.5 billion hack in February 2025. Bybit is updating its LazarusBounty platform to help track stolen funds, Zhou added.
