Bitget reported an unauthorized transfer of approximately $351.6 million from its hot and warm wallet infrastructure on Thursday, prompting the exchange to suspend withdrawals. CEO Gracy Chen told users in a live Q&A on X that preliminary forensic analysis identified IP addresses matching VPN services previously used by a North Korean hacking group. She said the pattern mirrors earlier attacks attributed to the DPRK, and that the breach does not appear to be an insider operation.
According to Chen, the attackers moved funds directly from Bitget’s systems rather than forging user withdrawal requests or compromising private keys of cold, hot or warm wallets. Investigators are still assessing which components of the platform were accessed and how the intrusion occurred.
The exchange disclosed that a portion of the stolen assets has been recovered, though no specific amount was provided. Bitget is cooperating with blockchain foundations and other partners to trace and retrieve the remaining funds.
North Korean cyber actors have been linked to an estimated $2.02 billion in cryptocurrency theft in 2025, including the roughly $1.5 billion Bybit hack that the FBI attributed to the same state‑sponsored group. Chen cited these prior incidents as further evidence supporting the attribution.
Withdrawals remain halted while Bitget completes its investigation and implements additional security measures. The exchange has not indicated a timeline for resuming normal operations.











