Bitget CEO suspects North Korea behind $352M hack, citing IP clues

Bitget CEO Gracy Chen said preliminary analysis suggests North Korean-linked hackers may be responsible for an unauthorized transfer that saw roughly $351.6 million taken from the exchange, citing IP addresses tied to VPN services used by a DPRK group. An independent onchain researcher, Specter, separately reported tracing some stolen funds through wallets previously connected to an exploiter linked to a suspected North Korea-affiliated collective.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished about 1 hour agoUpdated about 1 hour ago0 views
Bitget CEO suspects North Korea behind $352M hack, citing IP clues

Why It Matters

The claim ties a major crypto exchange theft to a pattern of state-linked cybercriminal activity, echoing prior large-scale losses attributed to North Korea and highlighting ongoing challenges in securing custodial wallet infrastructure and tracing cross-chain thefts.

Key Facts

  • Incident amount: $351.6 million (reported)
  • Alternate rounded figure: $352 million (reported elsewhere in coverage)
  • CEO: Gracy Chen
  • Preliminary link: IP addresses matching VPN choices associated with a DPRK group
  • Onchain researcher: Specter

Bitget CEO Gracy Chen said a preliminary investigation into the exchange’s recent security breach has identified IP addresses consistent with VPN services used by a North Korea-linked hacking group. Chen made the remarks during a live Q&A on X following the incident, and said investigators observed similarities with prior attacks attributed to DPRK actors.

Chen explained that the attackers compromised a backend system of the wallet service and manipulated transfer information to trigger authorizations, rather than forging user withdrawal requests or obtaining private keys for cold, hot or warm wallets. She added that the exchange does not currently believe the incident was an inside job and that teams are still mapping which systems were affected and how access was obtained.

An independent onchain researcher using the handle Specter separately reported tracing some of the stolen XRP through an Ethereum address that received 68,808 USDT from a wallet. That wallet had previously sent ETH to an address labeled “AFX EXPLOITER.” AFX — which suffered a $24 million hack in July — had linked that incident in its postmortem to a group called TraderTraitor, which is suspected to have DPRK ties.

Bitget confirmed unauthorized transfers impacted portions of its hot and warm wallet infrastructure and suspended withdrawals after the attack. Chen said some stolen funds have been recovered but did not provide a figure, and she said the exchange is collaborating with blockchain foundations and other partners on recovery and investigation efforts. The broader context notes that North Korean actors were linked to an estimated $2.02 billion in crypto theft in 2025, including the roughly $1.5 billion Bybit breach that the FBI attributed to North Korea.

Keep Reading