Skip to main content
Emerging ThreatsData Breaches

North Korea Targets Bitget in $387.5M Crypto Heist

Sleek cryptocurrency trading terminal with screens and desktop computer in a bright, empty trading floor.

“Hackers breached a key backend system of the wallet service and exploited it to forge transfer information and invoke the authorization signing process, thereby transferring funds out,” Chen said.

Chen on the intrusion and the revised loss figure

The CEO of crypto exchange Bitget, identified in reporting only as Chen, confirmed a cyberattack that she says bears the technical hallmarks of a North Korean operation and resulted in the theft of roughly $387.5 million in digital assets. Bitget initially estimated the loss at $351.6 million but revised the figure to $387.5 million after identifying additional affected assets on Zcash and TRON that were not included in the first calculation.

Chen told users that Bitget’s cold wallets and customer balances were unaffected, and that the company’s User Protection Fund held more than $464 million in assets “all held in publicly verifiable wallets.” She added: “beyond the $464M+ Protection Fund … Bitget holds over $1 billion in its own assets,” and asserted that “User funds are covered on a 1:1 basis.” Withdrawals were temporarily suspended while additional security checks were completed; deposits and trading remained possible, the company said, because Bitget Wallet (the self-custody product) operates on infrastructure separate from the exchange.

Chen ruled out private key leakage as a cause, describing that scenario as “a more severe risk” and saying it could be eliminated. She said damage control had been completed and “there is no risk of further fund outflows from the platform,” while adding that the specific intrusion methods remain under technical investigation and that a full report would be published on completion. Chen also told reporters that “IP behavioral patterns and on-chain signatures” suggested North Korean state‑sponsored actors.

Arkham’s timeline and the initial on-chain tally

Blockchain intelligence firm Arkham published preliminary observations that largely tracked the incident’s early movements on-chain. Arkham estimated roughly $350 million was stolen and said $228 million left Bitget wallets within an 18‑minute window, between 18:58 and 19:16 UTC. Arkham attributed $153 million worth of XRP to a wallet it identified as a Bitget cold wallet and reported additional takings across multiple asset types.

  • $153 million — XRP (from a wallet Arkham identified as a Bitget cold wallet)
  • $66.2 million — ETH
  • $34.8 million — USDT
  • $12.9 million — USDC
  • $12.8 million — Tether Gold on Ethereum

Arkham also flagged movement across several L2s and alternative chains as part of the dispersal pattern.

Networks affected: Zcash, TRON, Arbitrum, Optimism, BNB Smart Chain, Avalanche and Base

Bitget’s later asset accounting added Zcash and TRON holdings to the tally, triggering the revision from $351.6 million to $387.5 million. Beyond those two networks, Arkham’s early analysis showed withdrawals or transfers across Arbitrum, Optimism, BNB Smart Chain, Avalanche and Base, underscoring that the exploit touched assets on multiple chains and token standards.

Bitget said its own self‑custody product runs on infrastructure separate from the exchange environment, a distinction the company used to explain why deposits and trading continued while withdrawals were held for security checks.

Incident response, outside firms, and exchange solidarity

Bitget engaged incident response firm Mandiant and blockchain security company SlowMist to aid the investigation. The exchange also announced a bounty program offering 5 percent of funds successfully frozen or recovered to eligible participants who assist in tracing and freezing the stolen assets.

Executives at other exchanges publicly pledged support. Vugar Usi, CEO of MEXC, said “MEXC stands ready to support Bitget in any way we can.” Binance co‑CEO Richard Teng said Binance shared intelligence and helped trace the stolen funds. Ben Zhou, CEO of Bybit, said his company was “on standby to ‘help in any way we can,’” noting that Bitget had aided Bybit after a prior $1.5 billion theft the FBI attributed to North Korea in February 2025.

What this means for security teams, users, and competing exchanges

  • Security teams and incident responders: Bitget’s statement that a backend wallet service was compromised — and that private key leakage was ruled out — places scrutiny on backend authorization flows and signing logic. Firms running custodial services will likely prioritize forensic review of wallet‑service APIs and signing authorization chains.
  • Users and customers: Bitget emphasized that cold wallets and customer balances were not affected and highlighted a User Protection Fund of $464M+. Withdrawals remain suspended pending further checks; customers will watch the forthcoming technical report and any consumer remediation steps tied to the Protection Fund.
  • Competing exchanges and cooperative tracing: Public pledges from Binance, MEXC and Bybit — and the deployment of specialist responders — indicate continued cross‑exchange cooperation on tracing and recovery. The 5 percent bounty signals Bitget’s willingness to incentivize third‑party assistance to freeze assets on‑chain.

Bitget’s account narrows the immediate operational story: a backend wallet‑service compromise that allowed forged transfer instructions and authorized signatures, rapid multi‑chain asset movement across a concentrated time window, and an ongoing technical inquiry backed by major incident responders. The full technical report is pending, and the marketplace will now watch whether on‑chain tracing, third‑party cooperation and bounty incentives can reverse any portion of the $387.5 million loss.

Source: The Register