Bitget confirms $387.5M crypto theft, attributes attack to North Korea

Exchange revises loss upward; rival platforms pledge support as investigation continues

By LineZotpaper
Published
Read Time3 min
The CEO of cryptocurrency exchange Bitget has confirmed that a sophisticated cyberattack, bearing the hallmarks of a North Korean state-sponsored operation, resulted in the theft of approximately $387.5 million in digital assets from the exchange's wallets. The incident, which targeted the exchange's wallet service backend, temporarily suspended withdrawals but left cold wallets and customer balances unaffected.

Bitget initially estimated the loss at $351.6 million, but revised the figure to $387.5 million after identifying additional affected assets on Zcash and TRON that were not included in the initial tally. Blockchain intelligence company Arkham observed that roughly $350 million was stolen, with $228 million leaving Bitget’s wallets in just 18 minutes between 18:58 and 19:16 UTC. Arkham reported that $153 million worth of XRP was taken from a wallet it identified as a Bitget cold wallet, alongside $66.2 million of ETH, $34.8 million of USDT, $12.9 million of USDC, and $12.8 million of Tether Gold on Ethereum. Other affected networks included Arbitrum, Optimism, BNB Smart Chain, Avalanche, and Base.

Bitget CEO Chen (identified in source as Chen) said the exchange’s security team has identified the wallet service’s backend system as the source of the unauthorized transfers. “Hackers breached a key backend system of the wallet service and exploited it to forge transfer information and invoke the authorization signing process, thereby transferring funds out,” Chen explained. “The possibility of private key leakage can be ruled out – this means a more severe risk scenario has been eliminated. Damage control has been confirmed as complete, and there is no risk of further fund outflows from the platform.”

Chen assured users that Bitget’s cold wallets and customer balances remained safe, and that its User Protection Fund held more than $464 million in assets. “Beyond the $464M+ Protection Fund – all held in publicly verifiable wallets – Bitget holds over $1 billion in its own assets,” she said. “User funds are covered on a 1:1 basis.” Bitget Wallet, the company’s self-custody product, operates on separate infrastructure and was unaffected.

Chiefs at fellow exchanges rallied in support. “MEXC stands ready to support Bitget in any way we can,” said CEO Vugar Usi. “In moments like this, the industry is stronger when we stand together.” Binance co-CEO Richard Teng pledged Binance’s support, stating it had shared intelligence and helped trace the stolen funds. Ben Zhou, CEO of Bybit, said his company was on standby to help, noting that Bitget assisted Bybit following the $1.5 billion theft attributed to North Korea in February 2025.

Regarding attribution to North Korea, Chen noted that “IP behavioral patterns and on-chain signatures” suggest the involvement of North Korean state-sponsored attackers. Bitget has engaged incident response firm Mandiant and blockchain security outfit SlowMist to assist with the investigation. A full report is expected upon completion.

§

Analysis

Why This Matters

  • The theft underscores the persistent threat North Korean hacking groups pose to the cryptocurrency industry, following high-profile heists at Bybit, DMM Bitcoin, and WazirX.
  • Bitget’s quick containment and transparency about its Protection Fund may help restore user confidence, but the incident could trigger renewed regulatory scrutiny of exchange security practices.
  • The attack’s success against a major exchange raises questions about wallet infrastructure security and the effectiveness of current safeguards across the sector.

Background

Bitget, founded in 2018 and registered in the Seychelles in 2022, operates through regional hubs worldwide. This attack follows a pattern of large-scale cryptocurrency thefts attributed to North Korea, including the $1.5 billion Bybit heist in February 2025 that the FBI linked to state-sponsored hackers. North Korean groups have repeatedly targeted crypto exchanges and DeFi protocols to generate revenue for the regime, often using sophisticated social engineering and infrastructure breaches. The industry has responded with increased collaboration on threat intelligence and fund recovery, as seen in the support offered by Binance, MEXC, and Bybit.

Key Perspectives

Bitget (Exchange operator): Focuses on damage containment, user fund protection, and rapid investigation. CEO Chen emphasizes that cold wallets and the $464M+ Protection Fund cover user assets, and that the backend breach has been contained without private key compromise. Industry peers (Exchanges): Show solidarity and offer practical support—intelligence sharing and fund tracing—to prevent further damage and reinforce collective security norms. Binance and MEXC publicly pledge assistance. Critics/Skeptics: Users and security experts may question how a backend system could be breached to forge transfer authorizations. The timing and scale of the attack raise concerns about whether exchanges are investing enough in proactive defenses and whether user funds are truly safe even when cold wallets are claimed unaffected.

What to Watch

  • The full investigation report from Mandiant and SlowMist, expected to detail the intrusion methods and possibly identify the attackers with higher confidence.
  • Whether stolen funds are frozen or recovered through cooperation with blockchain intelligence firms and law enforcement.
  • Potential regulatory responses, especially in jurisdictions like Singapore, the US, or the EU, that may tighten cryptocurrency custody and security requirements.
  • Bitget’s ability to restore normal operations, including withdrawal resumption, and any long-term reputational or user outflow effects.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.