Bitget CEO Gracy Chen attributed a $352 million hack to North Korean attackers based on preliminary forensic evidence linking the breach to infrastructure used by known Democratic People's Republic of Korea (DPRK) hacking groups.
Chen disclosed that investigators traced IP addresses from the attack back to VPN endpoints commonly deployed by North Korean threat actors. The exchange did not immediately name which specific DPRK-linked group conducted the operation, but the technical fingerprinting represents a rare attribution claim in the crypto space, where most hacks remain unsolved or traced only to pseudonymous wallets.
The $352 million figure makes this one of the largest centralized exchange breaches on record. For context, FTX collapsed with roughly $8 billion in missing user funds, though that involved insolvency rather than a single hack. The Bitget incident ranks among the top exchange thefts alongside the 2014 Mt. Gox breach (850,000 BTC, worth billions today) and the 2022 Ronin sidechain exploit ($625 million), which U.S. officials also attributed to North Korea.
Bitget operates as a derivatives and spot trading platform with significant trading volume. The exchange has positioned itself as a competitor to Bybit and OKX in the Asian market. A breach of this scale threatens user confidence and regulatory standing, particularly given ongoing scrutiny of exchange security practices from regulators worldwide.
North Korea's involvement in crypto theft aligns with documented U.S. and international intelligence assessments. The country systematizes cybercrime as a revenue source, targeting exchanges, DeFi protocols, and blockchain bridges to fund its weapons programs and evade sanctions. The FBI and Treasury Department's Financial Crimes Enforcement Network (FinCEN) have previously warned about North Korean hacking campaigns extracting crypto assets. The Ronin hack exemplified this pattern. Lazarus Group, one DPRK unit, remains active across multiple attack vectors.
Chen's attribution statement raises questions about Bitget's security protocols and why attackers succeeded in extracting over a third of a billion dollars. The exchange typically requires multi-signature authorization and cold storage for large portions of user funds. A breach of this magnitude suggests either a compromise of private keys, an insider threat, or exploitation of a critical vulnerability in deposit or withdrawal systems.
The disclosure comes amid broader industry turbulence. Exchanges face mounting pressure to demonstrate robust security, transparency around reserve holdings, and compliance with AML/KYC frameworks. Bitget operates in a crowded market where reputation acts as a primary competitive moat.
Recovery efforts typically involve blockchain analysis firms tracking stolen assets across wallets and on-chain bridges. Stolen crypto often passes through mixers, cross-chain swaps, and centralized exchange withdrawals that offer weaker KYC enforcement. Law enforcement coordination with exchanges and blockchain analytics companies has improved marginally, but most stolen funds remain unrecovered.
Bitget faces immediate operational decisions around user reimbursement, insurance claims, and regulatory notification in each jurisdiction where it operates. The exchange also needs to rebuild trust through transparent communication about remediation steps, security audits, and enhanced monitoring going forward. Token holders and institutional clients will monitor the company's response closely.
