crypto

Bitget Accuses North Korea of a $352M Heist and Details the On-Chain Investigation

Gracy Chen, Bitget’s CEO, accuses North Korea of being behind a hack that resulted in the theft of $351.6 million. The on-chain investigation reveals traces of XRP and USDT sent to a wallet linked to the AFX incident, while U.S. authorities have already attributed over $2 billion in crypto losses to Pyongyang in 2025.

TR
dimanche 27 septembre 2026 à 04:30Updated lundi 28 septembre 2026 à 05:055 min
Partager :Twitter/XFacebookWhatsApp
Bitget Accuses North Korea of a $352M Heist and Details the On-Chain Investigation

Bitget confirmed yesterday a security breach that allowed the theft of $351.6 million, and its CEO, Gracy Chen, immediately pointed to North Korea as the likely perpetrator, citing IP addresses matching VPN services associated with a North Korean hacking group. The platform suspended withdrawals as early as Thursday, September 24, 2026, citing a compromise of its hot and warm wallet systems (CoinTelegraph).

Bitget Points to North Korea as Culprit for $352M Heist

During a live Q&A session on X, Gracy Chen declared: “We have identified IP addresses that correspond to the VPN choices of a certain DPRK group,” emphasizing the striking similarities with previous attacks attributed to Pyongyang. She added that the investigation does not consider an insider scenario, thus ruling out any internal involvement (CoinTelegraph).

On the same day, the CEO clarified that the hackers exploited the transfer authorization signing system without stealing the private keys of cold, hot, or warm wallets. This method, she explained, “did not forge users’ withdrawal requests,” but allowed for the falsification of transfer information at the backend (CoinTelegraph).

On-Chain Analysis: Traces of XRP and USDT Sent to AFX EXPLOITER Wallet

The renowned on-chain researcher known as Specter published an independent analysis showing that some of the stolen XRP had been converted into 68,808 USDT and sent to an Ethereum address that previously transferred funds to a wallet labeled “AFX EXPLOITER.” This address was already linked to the $24 million loss suffered by AFX in July, an incident the company attributed to a group named TraderTraitor, reputedly connected to North Korea (CoinTelegraph).

Specter highlighted that the same wallet received Ethereum before sending the USDT, creating a chain of transactions that strengthens the theory of a coordinated operation between several North Korean hacking groups. Tracking these on-chain flows constitutes one of the most tangible proofs linking the Bitget heist to actors already identified in other attacks (CoinTelegraph).

The North Korean Attack Model: Compromise of the Portfolio Service Backend

According to Gracy Chen’s statements, the attackers infiltrated the backend system of Bitget’s portfolio service and manipulated the transfer authorization process. This technique, which does not require access to private keys, allows for the generation of fraudulent withdrawal instructions while leaving cold and hot wallets intact, thereby limiting the immediate impact of the loss but complicating recovery (CoinTelegraph).

This modus operandi corresponds to the patterns observed in other cyberattacks attributed to North Korea, where hackers prioritize the spoofing of internal protocols over the direct theft of cryptographic keys. This approach makes early detection difficult, as transaction logs can appear legitimate as long as authorization signatures are not meticulously verified.

Ongoing Investigation and Initial Refunds: Some Funds Recovered

Gracy Chen indicated that, despite the severity of the incident, part of the stolen funds had already been recovered, though she did not specify the exact amount. The platform is collaborating with several blockchain foundations and technological partners to trace and return the assets, a process that aligns with protocols for responding to major incident responses (CoinTelegraph).

U.S. authorities, including the FBI, have already attributed over $202 million in crypto losses to North Korea in 2025, suggesting that Bitget’s recovery efforts benefit from experience in similar cases. The recovery process remains lengthy, as actors must follow on-chain trails to liquidity exchanges and mixing services.

North Korean Cyber-Attack History in Crypto, 2025-2026

In 2025, North Korea-affiliated hackers were responsible for an estimated $202 million in crypto thefts, including the pirating of Bybit, valued at around $1.5 billion, attributed by the FBI to the same group. These operations often used VPNs and anonymization services to mask their origins, a factor confirmed in Bitget’s preliminary investigation (CoinTelegraph).

The case of AFX, which lost $24 million in July, also illustrates the continuity of tactics: the TraderTraitor group, already suspected of being linked to North Korea, would have exploited similar vulnerabilities in portfolio signing systems. The repetition of these patterns indicates a methodical evolution aimed at circumventing traditional security controls of exchanges (CoinTelegraph).

Implications for Exchange Security and Investor Confidence

The immediate suspension of withdrawals by Bitget has sent shockwaves among users, leading to increased volatility in the prices of affected tokens on spot markets. While Bitcoin’s price did not experience significant fluctuations in the 24 hours following the announcement, trading volumes on several exchanges increased by 12% according to aggregated data (CoinTelegraph).

This incident intensifies regulatory pressure on global exchanges to strengthen their key management protocols and on-chain transaction monitoring systems. Investors, particularly those active on leveraged trading platforms, should closely monitor announcements regarding fund recovery and security enhancement measures implemented by Bitget and its competitors.

Was this article helpful?

Commentaires

Connectez-vous pour laisser un commentaire