Crypto exchange Bitget believes North Korean hackers may be responsible for a security breach involving approximately $351.6 million in digital assets, citing preliminary findings from an ongoing investigation.

Bitget CEO Gracy Chen said investigators found IP addresses associated with VPN services previously linked to a North Korean hacking group. She added that the attack pattern appeared similar to earlier operations attributed to the country during a livestream on X.

Chen said the exact method used to access Bitget’s systems is still being examined by technical investigators.

Bitget detected unauthorized transfers from certain wallets on Thursday afternoon in the United States. The activity involved 19 transfers from parts of the exchange’s hot and warm wallet infrastructure, while its cold wallets remained secure, according to Chen.

The affected assets included ether, XRP, USDT, USDC, Avalanche and BNB across the Ethereum, XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum networks. Early on-chain estimates placed the outflows at around $183 million, but Bitget said those figures did not account for activity across all impacted blockchains.

The exchange’s security team determined that the attacker gained access to a critical backend wallet system, used it to falsify transfer information and triggered Bitget’s authorization-signing process. Chen said the breach had been contained, stopping any further unauthorized withdrawals.

“Private key compromise has been ruled out,” she said.

Withdrawals remain paused while technical teams repair and strengthen the affected systems, though deposits and trading are continuing as usual.

Chen did not provide a firm timeline for restoring withdrawals, but said the process could take hours or days and “shouldn’t take weeks,” according to a broadcast on X several hours after the incident.

Bitget said customer balances remain accurate and that the loss is fully covered by its User Protection Fund, which holds more than $464 million.

Bybit CEO Ben Zhou said his team was ready to assist Bitget, which had previously supported Bybit after its $1.5 billion hack in February 2025. Zhou added that Bybit is updating its LazarusBounty platform to help trace the stolen funds.

Source link

Exit mobile version