Security/ crypto · north korea · bitget · security

North Korea Blamed for $387 Million Bitget Crypto Exchange Hack

Bitget says North Korea-linked hackers drained $387 million using forged wallet approvals, and its protection fund will cover the loss.

Someone forged approval signatures on Bitget's backend wallet system and walked away with $387 million in crypto - and investigators think it was North Korea.

Bitget CEO Gracy Chen said hackers exploited the exchange's backend wallet system on September 24, forging transfer approvals that tricked it into authorizing fraudulent transfers from hot wallets. The stolen haul spanned ETH, XRP, USDT, USDC, Avalanche, and BNB across five different networks. Chen cited IP addresses tied to VPN infrastructure previously used by North Korean hacking groups. Early on-chain estimates put the loss at $170 million to $183 million before Bitget's own audits settled on a final figure of $387.5 million.

The laundering was the fast part. Attackers converted stablecoins and tokenized gold into ETH within minutes specifically to dodge blacklisting, then splintered unfreezable assets like XRP and BNB across dozens of wallets - a playbook that's becoming routine for state-linked crypto theft. Bitget says its $464 million protection fund covers the full loss and that cold wallets stayed untouched, but the speed of the laundering shows exchanges are still reacting to these attacks, not stopping them.

It's the third nine-figure crypto hack in recent months, after Liquid Network's $320 million loss and Drift's $270 million hack in April. If North Korea's involvement holds up, it extends a pattern that includes the $1.5 billion Bybit theft the FBI pinned on Pyongyang in February 2025.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →