Signal

Bitget CEO Gracy Chen says she suspects North Korean attackers exploited a backend system used to process wallet transactions to drain $387M from the platform

First reported by Fortune ·

The signal ●●●○ Compiled by AI from Fortune, Techmeme, The Register, Bitget, Financial Times and 24 more
Why you might care

Your crypto exchange's internal approval systems are now a potential attack vector for unprecedented scale hacks.

What happened

Crypto exchange Bitget has reported a security breach resulting in the loss of over $387 million, marking the largest crypto hack of the year. Bitget CEO Gracy Chen stated that the platform suspects North Korean attackers exploited a backend system for processing wallet transactions. Instead of stealing private keys, the attackers manipulated the exchange's internal approval system to authorize fraudulent withdrawals. The vulnerability has since been fixed, and withdrawals were temporarily paused for security reviews. The stolen funds were primarily from Bitget's hot and warm wallets, with the separate self-custodial Bitget Wallet remaining unaffected. North Korea is a significant actor in crypto theft, reportedly stealing billions annually to circumvent international sanctions. Bitget has partnered with Mandiant and SlowMist for the investigation and launched a recovery bounty program, assuring users its $464 million user protection fund can cover the loss if funds are not recovered.

What it means

The attack on Bitget highlights a critical shift in cryptocurrency exploits, moving beyond direct private key theft to sophisticated manipulation of backend transactional processing systems. This implies that even exchanges with robust private key security measures can be vulnerable if their internal authorization workflows are compromised. The scale of the loss underscores the escalating sophistication and financial motivation behind state-sponsored cybercrime, particularly from entities like North Korea, which increasingly rely on illicit digital asset acquisition to fund operations amid sanctions.

This incident will likely pressure exchanges to invest more heavily in auditing and securing their internal approval mechanisms and transaction processing logic, rather than solely focusing on cold storage and private key protection. The continued targeting of exchanges, even those with substantial protection funds, suggests a persistent and evolving threat landscape that may necessitate greater industry-wide collaboration on threat intelligence sharing and proactive vulnerability discovery to protect user assets.

AI-written summary. May contain errors.