Bitget suspects North Korea in $387.5M crypto exchange hack
Bitget CEO Gracy Chen said a September 24 breach that drained $387.5 million from the exchange showed signs of North Korean state-sponsored hackers, pointing to VPN infrastructure previously linked to such groups. Attackers exploited a backend wallet system, forging transfer approvals to authorize fraudulent withdrawals, while cold wallets and private keys stayed secure. Bitget froze withdrawals temporarily and said its $464 million User Protection Fund would cover the entire loss.
GoKawiil's interpretation of the reporting above, not reported fact.
The rapid laundering of stolen funds—converting stablecoins to untraceable ETH within minutes—illustrates how quickly attackers can evade blacklisting efforts, which may pressure exchanges to speed up detection systems. If confirmed, North Korean involvement would extend a pattern of state-linked crypto theft used to fund national programs, according to past assessments by researchers and governments. Bitget's use of a reserve fund to cover losses could become a model other exchanges point to when reassuring users after breaches.
- Bitget's CEO says the $387.5 million hack likely involved North Korean state-sponsored actors based on IP evidence.
- Attackers forged transfer approvals in a backend wallet system while cold wallets remained untouched.
- Bitget pledged to cover losses via its $464 million User Protection Fund and resume withdrawals in stages from September 28.
Ledger Nano X Hardware Wallet — This story is a stark reminder that exchange hot wallets can be compromised even at large platforms. A hardware wallet like the Ledger Nano X keeps your private keys offline and out of reach of exchange-based exploits like this one. It's a smart way to take custody of your own crypto rather than trusting it entirely to a centralized exchange.
See Ledger Nano X Hardware Wallet on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: tomshardware.com — Etiido Uko, 2026-09-28
Published there as: “North Korea named as primary suspect in $387 million Bitget crypto hack”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.