North Korea Suspected in $351 Million Bitget Crypto Heist
North Korea suspected in $351 million Bitget crypto heist.
Summary
Cryptocurrency exchange Bitget has reported a significant heist totaling approximately $351.6 million in digital assets. The exchange's CEO indicated that the attack methods used closely resemble those of known North Korean hacker organizations, based on IP behavior and on-chain analysis. While the specific threat group has not been named, the incident involved compromising a critical backend system in the wallet infrastructure, leading to fraudulent transfers from hot wallets.
Full text
Cryptocurrency exchange Bitget says the hackers who stole roughly $351.6 million in digital assets from its systems used techniques that closely resemble those of known North Korean threat actors. “Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations,” Bitget CEO Gracy Chen said in a Friday post on X. Chen’s post did not name a specific threat group, and Bitget has not detailed the evidence behind its assessment. She said the incident has been reported to the relevant authorities. Founded in 2018, Bitget runs a centralized exchange for spot and derivatives crypto trading. It also offers Bitget Wallet, a self-custodial wallet that the company says runs on separate infrastructure and was not affected. Bitget said its security systems caught the unauthorized transfers on September 24. The funds came from a small number of the exchange’s hot wallets. According to the company, its cold wallets were not touched. The stolen funds include ETH, XRP, BNB, AVAX, USDT and USDC, spread across several blockchains. XRP accounts for the largest loss on a single chain. According to Chen, some blockchain foundations have frozen wallet addresses linked to the attacker.Advertisement. Scroll to continue reading. The company hasn’t yet worked out how the attacker got in. However, it said the hacker compromised a critical backend system in its wallet infrastructure and abused it to get fraudulent transfers approved. Bitget said private keys were not compromised. Mandiant and blockchain security firm SlowMist are helping with the investigation. North Korean state-sponsored hackers have stolen billions of dollars’ worth of cryptocurrency in recent years. The FBI blamed North Korea for the February 2025 heist in which roughly $1.5 billion was stolen from Bybit. Related: $290 Million Kelp DAO Crypto Heist Blamed on North Korea Related: CryptoBandits Malware Doubles as a Backdoor, Abuses Tor Related: Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public DataOT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS IntegratorsUS Court Sentences Armenian Man to Prison for Ryuk Ransomware AttacksHoneywell: OT Security Teams Embrace AI, but Autonomy Still RareAI-Powered Phishing Platform EvilTokens Disrupted by MicrosoftShinyHunters Claims FBI Hack, Demands Retraction of Threat ReportNightmare Eclipse Drops New Microsoft Defender Exploit After Revealing IdentityOnly 13% of OT Network Segments Are Fully Isolated: Analysis Latest News In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility ExposureCISA Election Security Plan Flags Patching Barriers, Voter Database AttacksKosovar Owner of Rydox Marketplace Pleads Guilty in US CourtWindows, Linux, Android File Notification Systems Leak User Activity‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data ExfiltrationRoundcube Webmail Vulnerability in Attackers’ CrosshairsAutonomous AI Hacks Raise Thorny Questions of Legal AccountabilityKontext Security Emerges With $4 Million for AI Agent Runtime Controls Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveDoppel has named Joey Rachid as Chief Security Advisor and Field Chief Information Security Officer.Delinea has appointed Timothy Regan as Chief Financial Officer.Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.More People On The MoveExpert Insights Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- malware — CryptoBandits