CEO Cites IP Evidence Tying Breach to DPRK Cyber Group
Gracy Chen, chief executive of Bitget, told followers in a live Q&A session on X that preliminary forensic work points to North Korean actors as the likely perpetrators behind the exchange's $351.6 million security breach that struck on Thursday.
Chen explained that security investigators had flagged IP addresses in the attack trail that corresponded to virtual private network configurations previously associated with a Democratic People's Republic of Korea (DPRK) hacking collective. "We've identified some IP addresses that match the VPN choices by a certain DPRK group," she stated, drawing a direct parallel to earlier operations attributed to the same state-sponsored actors.
She went on to describe the overall signature of the intrusion as closely resembling methods the North Korean team had employed in past campaigns. "The pattern looks very much like what the North Korean team did before," Chen noted, reinforcing the exchange's working hypothesis.
Attack Mechanics and What Was Not Compromised
A critical detail Chen provided was that the attackers did not fabricate user withdrawal requests to siphon funds. Instead, the hackers breached Bitget's internal systems and moved money directly through the platform's infrastructure. She specifically ruled out the theft of private keys from cold, hot, or warm wallets.
"They did not forge user withdrawal requests, nor did they obtain our private keys of the cold wallet and any hot, warm wallet," she clarified, indicating the compromise lay elsewhere in the exchange's operational stack.
Chen acknowledged that investigators were still piecing together exactly which internal systems had been accessed and the precise pathway the attackers used to gain entry. At the time of publication, Bitget had confirmed unauthorized transfers affecting portions of its hot and warm wallet infrastructure, and all customer withdrawals remained suspended.
Chen also made clear that the exchange does not consider the incident an inside job, a statement that narrows the investigation's focus toward an external, highly sophisticated threat actor.
Broader Context: North Korea's Crypto Crime Surge
The Bitget incident lands amid a dramatic escalation in state-sponsored cryptocurrency theft. According to figures cited in reporting, North Korean hackers were connected to an estimated $2.02 billion in crypto-related theft across 2025. That total includes the roughly $1.5 billion Bybit exchange breach, which the U.S. Federal Bureau of Investigation publicly attributed to North Korean state actors.
The convergence of these events underscores a pattern in which DPRK-linked groups have increasingly targeted major cryptocurrency exchanges, leveraging advanced network techniques and VPN-based anonymization to mask their origin.
Recovery Efforts Underway
During the same live broadcast, Chen disclosed that a portion of the stolen funds had already been recovered, though she declined to specify a dollar figure. She said Bitget was coordinating with blockchain foundations and other industry partners to trace and reclaim remaining assets.
The statement offered a measure of reassurance to affected users, even as the full scope of the breach and the identity of the responsible group remain under active investigation.
