[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fkMqUDDQFB4HGcuWyOVryTy2Bv6g4kbBFq8kr0vflTp8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":27,"created_at":28,"published_at":29,"article":30,"tags":34,"podcasts":53},"329efe77-6ece-48c1-a34f-5be24e637393","north-korean-hackers-exploit-backend-compromise-to-drain-3516m-from-bitget","851fbfa5-750d-4ea3-b842-e32e079bb9de","North Korean Hackers Exploit Backend Compromise to Drain $351.6M from Bitget","Attackers suspected to be North Korean state-sponsored actors compromised Bitget's backend wallet infrastructure and spoofed transaction data to siphon funds from hot and warm wallets — the highest-risk storage tier in any crypto exchange. The root cause centers on insufficient access controls and segmentation around backend systems that had direct authority over live wallet operations. This attack illustrates the catastrophic financial and reputational damage that results when privileged backend systems are reachable, poorly monitored, and able to authorize large-scale fund movements without additional verification layers. The fact that cold wallets remained secure confirms that air-gapped, isolated storage can limit blast radius, but the hot\u002Fwarm wallet exposure was devastating. Incidents of this magnitude underscore why cryptocurrency platforms are prime targets for sophisticated nation-state actors seeking to fund sanctioned regimes.","**Immediate actions:**\n- Suspend and rotate all backend service credentials, API keys, and privileged access tokens associated with wallet infrastructure.\n- Enforce multi-party authorization (MPC) or multi-signature requirements for any transaction above a defined threshold from hot or warm wallets.\n- Isolate backend wallet systems behind strict network allowlists, permitting only explicitly approved internal services to communicate with them.\n\n**Long-term improvements:**\n- Implement hardware security modules (HSMs) and privileged access workstations (PAWs) for all systems that can authorize fund movements.\n- Minimize funds held in hot and warm wallets to the operational minimum, moving the majority of reserves to cold storage.\n- Conduct regular red team exercises specifically targeting wallet infrastructure and backend transaction pipelines.\n\n**Detection measures:**\n- Deploy real-time anomaly detection on transaction volumes and patterns, with automated circuit-breaker rules that halt withdrawals when thresholds are breached.\n- Aggregate and continuously monitor backend system logs in a SIEM with alerts for any transaction data modification or spoofing indicators.\n- Establish a threat intelligence feed focused on North Korean APT TTPs (e.g., Lazarus Group) and apply relevant IOCs to endpoint and network detection rules.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25,26],"CIS Control 4 – Controlled Use of Administrative Privileges","CIS Control 12 – Network Infrastructure Management","CIS Control 13 – Network Monitoring and Defense","NIST SP 800-53 AC-2 – Account Management","NIST SP 800-53 AC-6 – Least Privilege","NIST SP 800-53 SI-3 – Malicious Code Protection","NIST SP 800-53 SC-7 – Boundary Protection","NIST SP 800-53 IR-4 – Incident Handling","NIST Cybersecurity Framework DE.CM-1 – Network Monitoring","NIST Cybersecurity Framework PR.AC-4 – Access Permissions","MITRE ATT&CK T1565 – Data Manipulation","MITRE ATT&CK G0032 – Lazarus Group (North Korea)","ITIL Service Operation – Incident Management","ISO\u002FIEC 27001 A.9 – Access Control","ISO\u002FIEC 27001 A.13 – Communications Security","published","2026-09-25T12:21:08.372742+00:00","2026-09-25T12:21:08.081+00:00",{"id":7,"url":31,"slug":32,"title":33},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fbitget-says-suspected-north-korean.html","bitget-says-suspected-north-korean-hackers-stole-351-6m-after-backend-compromise-0fba6d","Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise",[35,41,47],{"id":36,"name":37,"slug":38,"description":39,"color":40},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":42,"name":43,"slug":44,"description":45,"color":46},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":48,"name":49,"slug":50,"description":51,"color":52},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[]]