Suspected North Korean hackers steal $351.6 million from Bitget in backend wallet breach

· CyberSecurity

TLDR

  • Suspected North Korean hackers stole roughly $351.6 million from Bitget's hot and warm wallets after compromising a backend wallet-service system.
  • Attackers forged transaction data to bypass authorisation and move funds across seven blockchains, including Ethereum, the XRP Ledger and Arbitrum.
  • Bitget says cold wallets and the majority of platform assets are unaffected, and losses will be covered by its 5,500 BTC User Protection Fund.
  • The exchange has brought in Mandiant and SlowMist to investigate, and some blockchain networks have already frozen the attackers' wallet addresses.

Bitget disclosed that suspected North Korean hackers stole approximately $351.6 million from the exchange's hot and warm wallets after compromising a critical backend system within its wallet infrastructure.1 The exchange's security systems flagged multiple unauthorised transfers on Thursday evening, and Bitget temporarily suspended withdrawals while it investigated.1 According to chief executive Gracy Chen, attackers used the compromised backend to spoof transaction data and trigger the wallet service's authorisation process, moving funds out across Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base.2 Chen said the intrusion's pattern, based on IP behaviour and on-chain analysis, is "highly consistent with known patterns of North Korean hacker organisations."12

Bitget says its cold wallets and the overwhelming majority of platform assets remain secure, and that the self-custodial Bitget Wallet, which runs on separate infrastructure, was not affected.1 Customer balances remain accurate and deposits and trading continue as normal, the exchange said, adding that losses will be covered by its User Protection Fund, which holds 5,500 BTC worth roughly $464 million.1 Some of the affected blockchain networks have already frozen the attackers' wallet addresses, and Bitget is working with law enforcement alongside Mandiant and SlowMist on the investigation.12

Why it matters: this is one of the largest crypto exchange breaches of the year, and it shows state-linked hackers increasingly targeting backend wallet infrastructure and authorisation systems rather than phishing individual users, which makes these thefts harder to stop with account-level security alone.

Sources

  1. Hackers steal $351.6 million in Bitget crypto exchange hack (BleepingComputer)
  2. Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise (The Hacker News)