Cryptocurrency exchange Bitget says its $351.6 million security breach is likely linked to North Korean hacking operations, based on preliminary IP and on-chain analysis.
Bitget detected unauthorised transfers from some of its hot wallets on September 24 and subsequently suspended customer withdrawals as a security precaution. The exchange said the affected assets were held in portions of its hot and warm wallet infrastructure, while its cold wallets remained secure.
Bitget CEO Gracy Chen said preliminary investigations had identified IP addresses whose VPN patterns matched those associated with a North Korean hacking group. She said the attack method also showed similarities with previous attacks attributed to North Korean cyber actors.
The attribution has not yet been independently confirmed. Bitget said its investigation remains ongoing and that it has notified law-enforcement agencies and blockchain security firms.
According to Bitget’s preliminary findings, the attackers compromised a critical backend system within its wallet infrastructure. The system was allegedly used to manipulate transaction information and trigger the exchange’s normal authorisation process to move funds.
Chen said the attackers did not obtain the private keys to the affected wallets. Investigators are still working to determine precisely how the attackers initially gained access to the backend system.
Bitget estimates that approximately $351.6 million in crypto assets were affected. The stolen assets reportedly included XRP, Ethereum, USDT, USDC, BNB, AVAX and other tokens across several blockchain networks.
The exchange says customer balances remain accurate and that the loss is covered by its User Protection Fund, which holds more than $464 million. Deposits and trading remain operational, while withdrawals are temporarily suspended pending completion of the security review.
The suspected North Korean connection would place the incident among a long series of major cryptocurrency thefts attributed to cyber groups linked to Pyongyang. In 2025, the FBI attributed the $1.5 billion Bybit hack to North Korea.
Bitget has said it is working with blockchain networks, security firms and authorities to trace and recover the stolen assets. A full incident report is expected to provide further details on the attack and the measures being implemented to prevent a recurrence.
