$387.5 Million Bitget Hack Linked to Suspected North Korea Operation
Crypto exchange Bitget has been hit by a massive $387.5 million hack, with its security systems detecting unauthorized transfers from some of its hot wallets at 18:31 UTC on Thursday.
In an official incident notice and post on X, CEO Gracy Chen explained that the breach affected parts of Bitget's hot and warm wallet layers, but left cold wallets untouched. According to Chen, investigators have ruled out a private-key compromise, with the attacker instead compromising a critical backend system within their wallet infrastructure.
The hacker used this system to spoof transaction data, triggering Bitget's authorization process to move funds out. Chen revealed that the incident is still being investigated, with assistance from Mandiant and SlowMist. The crypto exchange has also put in place a recovery bounty, offering 5% for voluntarily freezing attacker funds and 5% for voluntary recovery.
Blockchain analytics firm Elliptic has assessed the attack as 'highly likely' to be linked to North Korea, pointing to on-chain ties between XRP taken from Bitget and ether from an earlier DPRK-attributed theft. MetaMask's Taylor Monahan had already noted that the loot landed in an address previously used for Bybit stolen funds.