
Bitget CEO Gracy Chen suspects North Korean state-sponsored hackers are behind the exchange's $351.6 million security breach, citing IP address analysis and attack patterns similar to previous inciden
Cryptocurrency exchange Bitget has suffered a significant security breach, with its CEO Gracy Chen pointing to North Korean state-sponsored hacking groups as the likely perpetrators. The incident involved unauthorized transfers of approximately $351.6 million from the exchange's hot and warm wallet infrastructure. Chen revealed this suspicion during a public Q&A session on X (formerly Twitter), where she discussed preliminary findings from the exchange's security investigation.
The investigation has identified specific IP addresses utilized during the breach that bear similarities to VPN services known to be associated with North Korean cybercrime operations. Furthermore, Chen noted that the attack methodology exhibited patterns consistent with previous sophisticated hacks attributed to North Korean hacking collectives. This evidence suggests a direct transfer of funds by the attackers, rather than exploiting user accounts or forging withdrawal requests, and differentiates it from an inside job.
This alleged involvement places Bitget's breach within a larger context of state-sponsored cybercrime. North Korean hacking groups have been extensively linked to cryptocurrency theft, reportedly amassing billions of dollars in stolen digital assets in recent years. Notably, the FBI has previously attributed a substantial portion of these illicit gains, including a major hack on the Bybit exchange, to actors operating under the directives of the Democratic People's Republic of Korea (DPRK).
In response to the breach, Bitget promptly suspended all withdrawal services to prevent further illicit outflows and secure its remaining assets. While the full extent of the compromised systems and the precise access vector are still under investigation, the exchange confirmed that private keys for its cold, warm, and hot wallets were not compromised. This detail is crucial as it suggests the attackers found a different vulnerability within the exchange's operational systems.
The market reaction to the news, while not directly causing a sharp downturn in major cryptocurrencies, adds to the ongoing concerns surrounding exchange security and the persistent threat of sophisticated cyberattacks. Such incidents underscore the inherent risks in digital asset trading and highlight the need for robust security measures and regulatory oversight. The recovery of some stolen funds, though unspecified in amount, indicates active efforts to mitigate the financial impact on the exchange and its users.
Traders and market observers will be closely monitoring Bitget's ongoing investigation for further details on the breach's root cause and the progress of fund recovery efforts. The exchange's ability to restore services smoothly and transparently will be critical for rebuilding user confidence. Additionally, any confirmed attribution to specific North Korean hacking groups could lead to increased scrutiny from international cybersecurity agencies and potential sanctions, impacting the broader landscape of digital asset security protocols.
Source: Cointelegraph. Summarized and rewritten by the Vexoda Newsroom. This is market news, not financial advice.