Key Takeaways
- Bitget CEO Gracy Chen said preliminary IP evidence and attack patterns may connect the $351.6 million breach to a North Korea-linked hacking group.
- The attackers moved funds directly from parts of Bitget’s hot and warm wallet infrastructure, while the exchange said cold wallets remained secure.
- The incident puts renewed focus on exchange backend security, operational controls and the growing financial impact of state-linked crypto theft.
Bitget is investigating a security breach involving approximately $351.6 million after unauthorized transfers were detected from parts of its hot wallet infrastructure. CEO Gracy Chen said preliminary findings, including IP addresses associated with VPN services previously used by a North Korean group, point toward possible DPRK involvement, although the attribution remains under investigation.
Preliminary IP Evidence Points to a Familiar Threat Actor
Chen said investigators identified IP addresses whose VPN usage matched choices associated with a North Korean hacking group and found similarities with previous attacks. She also said Bitget does not currently believe the incident was an insider attack.
The attribution is significant because North Korea-linked groups have been associated with some of the crypto industry’s largest thefts. Estimates cited in recent reporting put crypto assets stolen by North Korean actors at approximately $2.02 billion during 2025, including roughly $1.5 billion in the Bybit breach that U.S. authorities attributed to North Korea.
For institutional investors, the Bitget incident reinforces the importance of distinguishing blockchain-level security from exchange-level operational security. A compromised backend system can create material losses even when core private-key infrastructure remains protected.
Hot Wallet Exposure Becomes the Central Security Issue
Bitget said the breach affected portions of its hot and warm wallet layers, while cold wallets remained secure. Chen said the attackers transferred funds directly rather than forging customer withdrawal requests and did not obtain the private keys of the exchange’s cold, hot or warm wallets.
The exchange temporarily suspended withdrawals while investigators examined which systems were compromised and how access was obtained. Bitget also said its User Protection Fund held more than $464 million, exceeding the reported $351.6 million affected by the incident.
The scale of the breach is substantial relative to recent market activity. Bitcoin was trading around $84,789 on Sept. 25, up about 0.45%, after recording $60.99 billion-equivalent units in reported daily trading volume. The relatively contained market response suggests the incident has so far been viewed primarily as an exchange-specific security event rather than a systemic liquidity shock.
Institutional Risk Assessment Moves Beyond Private Keys
The incident also highlights a broader change in crypto security analysis. Institutions increasingly need to evaluate wallet architecture, transaction authorization systems, withdrawal controls and backend access alongside custody arrangements.
Bitget said some stolen funds had already been recovered, although Chen did not disclose the amount. The exchange is working with blockchain foundations and other security partners to trace and recover additional assets.
Security Investigation Will Shape the Next Market Response
The immediate priority is determining the initial access point, the exact systems compromised and the amount ultimately recovered. Whether the preliminary North Korea attribution is confirmed will also matter for the industry’s broader understanding of the attack. For exchanges and institutional participants, the episode underscores that resilient crypto infrastructure requires layered controls extending well beyond cold-wallet protection, particularly as transaction volumes and the financial value held on centralized platforms continue to expand.
Comparison, examination, and analysis between investment houses
Leave your details, and an expert from our team will get back to you as soon as possible