North Korean Hackers Hit Bitget for $387.5 Million in Spoofed Transfer Attack
Bitget's CEO Gracy Chen revealed that the exchange suffered a massive spoofed transfer attack, resulting in $387.5 million being stolen from its hot and warm wallet infrastructure.
The attackers compromised Bitget's backend system, allowing them to feed fake transaction data into the exchange's approval process.
Notably, the thieves never accessed any private keys or cold wallets, which hold the majority of customer funds.
The stolen assets were moved across eight blockchains in two timed bursts, with a significant portion being converted into Ethereum (ETH) within six minutes, at prices up to 5% above market rate.
Investigations suggest that the attack is linked to North Korea's Lazarus Group, which has been known for using similar tactics in the past.