North Korea-Linked Group Suspected in Bitget's $351.6 Million Hack
Bitget, a major cryptocurrency exchange, has been hit by a massive hack that saw $351.6 million worth of digital assets stolen from its hot wallet. The attack bears striking similarities to methods used by North Korean hacking groups, according to Bitget's CEO Gracy Chen.
The breach occurred on September 24, with the attackers gaining access to a critical backend system and manipulating transaction data to approve unauthorized transfers. Notably, private keys were not compromised in the incident, shifting the focus from classic key theft to a more sophisticated attack model involving internal system breaches and authorization process exploitation.
The stolen assets included ETH, XRP, BNB, AVAX, USDT, and USDC, with over 102 million XRP moved worth approximately $157 million. The company has temporarily suspended withdrawals and claims that user funds are covered by its User Protection Fund, which has more than $464 million.
Bitget's incident highlights the importance of multi-layered defense in crypto platforms, where a single compromised internal system can become a gateway for thefts of hundreds of millions of dollars. The investigation is ongoing, with Bitget working closely with security firms Mandiant and SlowMist to determine the cause of the breach.
The company has pledged to publish a full report on the cause of the breach and corrective measures. Until then, the connection to a North Korean group remains an estimate rather than a definitively confirmed identification.