- Bitget CEO Gracy Chen says preliminary evidence links the exchange’s $351.6 million breach to a North Korean hacking group, based on matching VPN-associated IP addresses.
- An independent researcher separately traced stolen funds to a wallet connected to TraderTraitor, a North Korea-linked group also blamed for the AFX exploit.
- Hackers exploited a backend wallet system to forge transfer authorizations but did not access cold wallet private keys or forge legitimate withdrawal requests; some funds have reportedly been recovered.
Bitget CEO Gracy Chen has pointed to North Korea as the likely source behind the exchange’s massive security breach, saying early investigation results show technical overlaps with attacks the country’s hackers have carried out before.
Speaking in a live Q&A on X following Thursday’s incident, Chen said her team had traced certain IP addresses back to VPN services previously tied to a North Korean hacking group. She was careful to note this wasn’t a confirmed attribution, but described the pattern as closely resembling the group’s past behavior. She also ruled out an inside job.
Live about Bitget Hot Wallet Incident on September 24, 2026 https://t.co/limZaY2pRf
— Bitget (@bitget) September 24, 2026
What Investigators Found So Far
Chen said the IP addresses uncovered during the review matched VPN choices associated with what she referred to as “a certain DPRK group” — shorthand for North Korea’s Democratic People’s Republic of Korea. She stopped short of naming a specific hacking unit but said the resemblance to prior incidents was strong enough to raise serious suspicion.
That suspicion lines up with a track record. North Korean-linked hackers were tied to an estimated $2 billion in stolen crypto during 2025 alone, including the roughly $1.5 billion Bybit hack that the FBI formally attributed to North Korean actors. If confirmed, Bitget would become the latest major exchange added to that list.
An Independent Researcher Draws the Same Line
Separately from Bitget’s internal findings, an onchain researcher going by Specter published their own analysis connecting the stolen funds to North Korean operations. According to Specter, some of the stolen XRP moved to an Ethereum address that had received a transfer of over 68,000 USDT from a wallet with a notable history — that same wallet had previously sent funds to an address labeled “AFX EXPLOITER.”
The connection matters because AFX, a platform hacked for $24 million back in July, said afterward that it suspected the attack came from TraderTraitor, a hacking group widely linked to North Korea. If the trail Specter identified holds up, it would add independent weight to Chen’s own findings.
How the Breach Actually Happened
Chen also offered more detail on the mechanics of the attack itself. She said hackers gained access to a backend system tied to Bitget’s wallet infrastructure and used that access to forge transfer information by exploiting the authorization signing process. Importantly, she said the attackers did not forge legitimate user withdrawal requests, and did not obtain private keys for the exchange’s cold wallets or its hot and warm wallets.
Investigators are still working to determine exactly which systems were breached and how the attackers first got in. Bitget has suspended withdrawals since the breach was first confirmed, and Chen said the exchange has already recovered some portion of the stolen funds, though she didn’t share a specific figure. The exchange said it’s continuing to coordinate with blockchain foundations and other industry partners on further recovery efforts.
The incident adds to a growing pattern of North Korea-linked breaches targeting crypto exchanges, underscoring how persistent — and increasingly sophisticated — these attacks have become across the industry.
Disclaimer: The information in this article is for general purposes only and does not constitute financial advice. The author’s views are personal and may not reflect the views of chainrant.com. Before making any investment decisions, you should always conduct your own research. chainrant.com is not responsible for any financial losses.