Bitget blames North Korea for $387.5M crypto wallet raid
First reported by The Register ·
Hackers exploited a backend system, not private keys, meaning the risk of further fund outflows from the platform is now eliminated.
Crypto exchange Bitget has confirmed that a cyberattack resulted in the theft of approximately $387.5 million in digital assets. The exchange's CEO, Gracy Chen, stated that the attack bore the hallmarks of a North Korean operation. Initially estimated at $351.6 million, the loss was revised upwards after identifying additional affected assets on Zcash and TRON. Blockchain intelligence firm Arkham noted that $153 million worth of XRP was taken from a Bitget cold wallet, alongside significant amounts of ETH, USDT, USDC, and Tether Gold. Bitget assured that its cold wallets and customer balances remained unaffected, and its User Protection Fund holds over $464 million in assets, with user funds covered 1:1. While withdrawals were temporarily suspended, trading and deposits continued. Bitget is working with Mandiant and SlowMist on the investigation, which points to a breach in a key backend system of the wallet service.
The attribution of the attack to North Korea, if confirmed, underscores the persistent threat posed by state-sponsored cybercriminal groups to the cryptocurrency ecosystem. These actors often leverage sophisticated tactics and exploit vulnerabilities in exchanges and wallet services to fund their regimes. The sheer volume of stolen assets also highlights the continued attractiveness of cryptocurrencies as a target for large-scale financial crime. Exchanges are forced to constantly adapt their security measures and incident response plans to counter these evolving threats.
Bitget's swift response, including transparency about affected funds and the User Protection Fund, aims to maintain customer confidence. However, the incident reiterates the critical need for robust, multi-layered security protocols across the industry, including proactive threat intelligence sharing between exchanges and security firms. The ongoing investigation into the specific intrusion methods used will likely yield valuable insights for the broader cybersecurity community, potentially informing future defense strategies against similar attacks.
AI-written summary. May contain errors.