Crypto exchange Bitget suspects North Korean hackers are behind a $352 million digital asset breach. Investigators identified IP addresses linked to VPNs previously used by North Korean hacking groups, and the attack pattern mirrors previous incidents attributed to the country.
The exchange has contained the breach and assured users that losses will be covered by its User Protection Fund, which holds over $464 million. Withdrawals remain suspended as systems are repaired.
Crypto exchange Bitget is pointing fingers at North Korean hackers following a major security breach that saw approximately $351.6 million in digital assets siphoned away. Preliminary findings from an ongoing investigation suggest that state-sponsored cybercriminals may be responsible for the massive theft.
Gracy Chen, chief executive officer of Bitget, during the Bitcoin Asia conference in Hong Kong, China, on Thursday, Aug. 27, 2026. The conference runs through August 28. Photographer: Chan Long Hei/Bloomberg via Getty ImagesBloomberg | Bloomberg | Getty Images
Gracy Chen, CEO of Bitget, revealed that investigators have identified internet protocol addresses linked to VPN services that have previously been associated with North Korean hacking operations. The modus operandi of the attack also bears a striking resemblance to earlier cyber offensives attributed to the isolated nation.
The breach occurred on Thursday afternoon stateside, with Bitget detecting unauthorized transfers from several of its hot and warm wallet infrastructure. In total, 19 transfers were made, impacting a range of digital assets including ether, XRP, USDT, USDC, Avalanche, and BNB across multiple blockchain networks such as Ethereum, XRP Ledger, Avalanche, BNB Smart Chain, and Arbitrum. While initial on-chain estimates placed the loss around $183 million, Bitget clarified that these analyses did not encompass activity across all affected blockchains.
According to Chen, the attacker gained access to a critical backend wallet system, which was then used to falsify transfer information and trigger Bitget's authorization-signing process. The exchange's security team has since contained the breach, successfully preventing any further unauthorized outflows. Chen also confirmed that a compromise of private keys has been ruled out.
During the investigation, withdrawals on the platform have been temporarily suspended to allow technical teams to repair and reinforce the affected systems. However, deposits and trading activities continue to operate normally. Chen indicated that withdrawals could be reinstated within hours or days, suggesting the disruption would not extend into weeks.
Bitget has assured its users that all customer balances remain accurate and that the full extent of the loss will be covered by its User Protection Fund, which boasts over $464 million in assets. In a gesture of solidarity, Bybit CEO Ben Zhou announced that his team is ready to assist Bitget, recalling how Bitget had supported Bybit following its own significant hack in February 2025. Bybit is also leveraging its LazarusBounty platform to aid in tracing the stolen funds.
Subscribe to our newsletter to get our newest articles instantly!
MARKET VOWS NEWSLETTER
Stop entering after the move is obvious.
Most traders wait for momentum, confirmation, and headlines. By then, the edge is gone.
Market VOWS shows you where behavior is becoming constrained — where capital is being forced, optionality is collapsing, and price is beginning to be imposed.