Cryptocurrency exchange Bitget said Thursday it suspects North Korean hackers are behind a security breach that stole approximately $351.6 million in digital assets, citing preliminary evidence from an ongoing investigation.
CEO Gracy Chen said investigators identified internet protocol addresses linked to VPN services previously used by a North Korean hacking group. The attack pattern also resembled earlier operations attributed to the country, she said in a livestream on X.
Bitget detected 19 unauthorized transfers from parts of its hot and warm wallet infrastructure on Thursday afternoon. Cold wallets remained secure. The specific intrusion method remains under technical investigation, Chen said.
Affected assets included ether, XRP, USDT, USDC, Avalanche and BNB across the Ethereum, XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum networks. Early on-chain estimates placed outflows at about $183 million, but Bitget said those analyses had not captured activity across all affected blockchains.
Chen said the attacker breached a critical backend wallet system, used it to spoof transfer information and triggered Bitget's authorization-signing process. The breach has been contained, preventing further unauthorized outflows, she said. "Private key compromise has been ruled out," Chen added.
Withdrawals remain suspended while technical teams repair and reinforce affected systems. Deposits and trading continue normally. Chen declined to commit to a firm timetable but said withdrawals could return within hours or days and "shouldn't take weeks."
The company maintains that customer balances are accurate and that the loss is fully covered by its User Protection Fund, which holds more than $464 million.
Bybit CEO Ben Zhou said his team was standing by to assist Bitget, which supported Bybit following its $1.5 billion hack in February 2025. Bybit is updating its LazarusBounty platform to help trace the stolen funds, Zhou added.











