Bitget Crypto Platform Hit by $387 Million Heist, North Korea Suspected
Crypto exchange **Bitget** has reported a massive security breach resulting in the theft of over $387 million. CEO **Gracy Chen** points to North Korean-linked hacking groups as the likely culprits, a pattern consistent with a growing number of sophisticated attacks targeting cryptocurrency platforms.
Singaporean crypto platform **Bitget** has disclosed a significant security incident, announcing that hackers stole more than $387 million from its exchange following a breach on Thursday.
**Bitget** CEO **Gracy Chen** held a town hall after the incident, stating that evidence links the theft to North Korean hackers. These groups have been responsible for billions in stolen funds from cryptocurrency platforms over the past five years.
Blockchain security firms initially observed over $175 million leaving the platform on Thursday, followed by larger unauthorized transfers. Chen confirmed that **Bitget**'s security team detected the transfers early and immediately activated emergency protocols.
The estimated losses stand at $387.5 million. Chen assured users that the company's **User Protection Fund**, which holds over $464 million, will cover all losses.
Withdrawals from the platform are currently suspended as **Bitget** collaborates with security firms **Mandiant** and **SlowMist** on recovery efforts. Law enforcement and other crypto platforms have been notified about the incident.
Further investigation revealed that hackers breached a backend system of **Bitget**'s wallet services, exploiting vulnerabilities to facilitate the unauthorized transfers.
"**Bitget** has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full," Chen affirmed.
The stolen assets include **ETH**, **XRP**, **USDC**, and several other cryptocurrencies. Chen noted that several platforms have already frozen some funds linked to the attackers' wallets. **Bitget** has also launched a recovery bounty program, offering 5% to platforms that voluntarily freeze attacker funds and another 5% upon successful recovery.
Later comments from Chen indicated that IP addresses, behavioral patterns, and on-chain signatures strongly suggest the attack is tied to North Korean-linked hacker groups.
"We have notified relevant authorities and are cooperating fully with them globally," Chen stated during the town hall.
Other blockchain experts have begun tracking the stolen funds, drawing parallels to past crypto thefts attributed to North Korea's **Lazarus Group**, a notorious hacking operation implicated in numerous high-profile heists.
According to **United Nations** investigators, North Korea's government stole over $2 billion in similar attacks last year and amassed $3 billion from cryptocurrency platform attacks between 2017 and 2023.
Earlier this year, North Korean hackers allegedly conducted two separate attacks, stealing $280 million from the crypto platform **Kelp** and another $290 million from the **Drift** crypto platform. These operations involved sophisticated tactics, including the use of fake companies and alleged actors.
During her town hall, Chen referenced North Korea's $1.5 billion theft from the Dubai-based platform **Bybit** last year, noting that **Bybit** successfully navigated the incident.
"If **Bybit** can hold on [after] a $1.5 billion loss, we can definitely hold on to a $350 million+ loss," she said. "Just like **Bybit** can hold on after their bank run and liquidity issue, we can too."