North Korean Hackers Linked to $388 Million Bitget Exchange Theft, CEO Says
Key Takeaways
- •North Korean hackers stole close to $388 million from Bitget, a figure the exchange's CEO revised upward by more than $30 million from her initial report of over $350 million.
- •Security firms flagged unauthorized transactions from Bitget's internet-connected hot wallets on Thursday, before the exchange announced it had frozen withdrawals.
- •Bitget CEO Gracy Chen said IP behavior patterns and on-chain analysis indicate the attack method is highly consistent with known North Korean hacker organizations.
- •The stolen assets consisted mostly of ethereum, tron, and USDT, although a stolen funds tracker shows the attacker holds more than $28.8 million in bitcoin.
- •Bitget, the world's sixth-largest crypto exchange with more than $1 billion in daily trading volume, has not confirmed a timeline for full recovery of funds or resuming withdrawals.

Hackers from North Korea targeted crypto exchange Bitget on Thursday, making off with close to $388 million in digital assets according to an update from the company's chief executive — a larger total than originally reported.
Bitget CEO Gracy Chen said Friday that the revised figure “reflects a more complete accounting of transfers during the incident.” She had first reported that over $350 million had been moved from the platform. The revision adds more than $30 million to the initial estimate.
Security firms first flagged unauthorized transactions from the Victoria, Seychelles-based exchange's hot wallets — the internet-connected wallets exchanges use to process customer withdrawals — on Thursday, before the company announced it had frozen withdrawals.
Bitget is the world's sixth-largest crypto exchange, processing more than $1 billion in trading volume per day, according to CoinGecko data.
“Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations,” Chen wrote on X on Friday.
She added: “Our goal is to complete a full recovery as soon as possible. We will announce the specific time window immediately upon confirmation.” No timeline has been confirmed yet, leaving users awaiting word on when withdrawals will resume.
In a security update, the exchange said it had identified the stolen digital assets, which consisted mostly of ethereum, tron, and the USDT stablecoin — and no bitcoin. A stolen funds tracker, however, shows that the attacker holds more than $28.8 million in the leading cryptocurrency. Because blockchain transfers are publicly visible, the movement of the stolen funds can be followed as the recovery effort continues.
Crypto-stealing criminals — particularly those linked to North Korea — have grown more sophisticated and faster since last year, and experts say artificial intelligence tools are enabling cyber criminals to work more efficiently. U.S. authorities have long alleged that hacking groups tied to the North Korean government, such as Lazarus, steal from crypto exchanges.
Crypto security has been thrust into the spotlight after a string of breaches this year have left the community reeling. In July, hackers exploited a firmware bug in the popular Coldcard bitcoin hardware wallet to steal nearly $120 million in user funds.
Earlier this month, purported white-hat hackers withdrew about 4,000 bitcoins — worth approximately $320 million at the time — from the federation wallet of Blockstream's Liquid sidechain. Days later, they returned 85% of the funds and demanded to keep the remainder as ransom.
This article is based on reporting by Mathew Di Salvo and was originally published on Bitcoin Magazine.