North Korean Hackers Suspected in $352M Bitget Breach, CEO Points to IP Evidence
According to Bitget's CEO Gracy Chen, early investigation results revealed IP addresses that correspond with VPN services linked to hacking groups from the DPRK.

According to Bitget's CEO Gracy Chen, hackers from North Korea could be responsible for the cryptocurrency exchange's $351.6 million security compromise that occurred on Thursday. Her assessment is based on initial investigation results that connected IP addresses to VPN platforms previously utilized by North Korean hacking operations.
During a live question-and-answer session on X that followed the security incident, Chen revealed that security experts investigating the breach had identified patterns consistent with earlier attacks attributed to North Korea. The exchange's leadership does not consider the possibility that this was an internal breach.
"We've identified some IP addresses that match the VPN choices by a certain DPRK group," Chen said, referring to the Democratic People's Republic of Korea.
North Korean hackers were linked to an estimated $2.02 billion in crypto theft in 2025, including the roughly $1.5 billion Bybit exchange hack, which the FBI attributed to North Korea.
"The pattern looks very much like what the North Korean team did before," she said.
Chen further revealed that the attackers penetrated Bitget's infrastructure and executed direct fund transfers, as opposed to creating fraudulent withdrawal requests on behalf of users.
"They did not forge user withdrawal requests, nor did they obtain our private keys of the cold wallet and any hot, warm wallet," she said.
Chen indicated that investigators continue to work on identifying which specific systems were penetrated and the methods the attackers employed to gain unauthorized access.
The statements follow Bitget's announcement of unauthorized fund transfers that impacted sections of its hot and warm wallet systems on Thursday. At the time of this publication, the platform's withdrawal functionality remains disabled.
Throughout the Q&A session, Chen additionally revealed that a portion of the stolen cryptocurrency had been successfully retrieved, though she declined to provide specific amounts. She indicated the exchange is collaborating with blockchain foundations along with additional partners in efforts to recover the stolen assets.