Bitget Blames North Korea for $387.5 Million Wallet Raid

AI-generated image · US National Wire
The exchange identifies a backend system breach as the source of the theft, claiming customer balances remain unaffected.
Crypto exchange Bitget has confirmed a cyberattack resulting in the theft of approximately $387.5 million in digital assets, as first reported by The Register. While the exchange initially estimated losses at $351.6 million, it later revised the figure upward after identifying additional stolen assets on TRON and Zcash.
Blockchain intelligence firm Arkham reported that roughly $228 million exited Bitget wallets within an 18-minute window. The stolen haul included $153 million in XRP from a cold wallet, $66.2 million in ETH, $34.8 million in USDT, $12.9 million in USDC, and $12.8 million in Tether Gold on Ethereum. Other impacted networks included Base, Avalanche, BNB Smart Chain, Optimism, and Arbitrum.
Bitget CEO Chen stated that the breach occurred via a key backend system of the wallet service, which allowed attackers to forge transfer information and trigger the authorization signing process. Chen noted that private key leakage was ruled out and asserted that customer balances and cold wallets remained unaffected. The company maintains a User Protection Fund exceeding $464 million and claims to hold over $1 billion in its own assets.
Chen attributed the attack to North Korean state-sponsored actors, citing on-chain signatures and IP behavioral patterns. The Register noted that North Korea has previously been linked to thefts at WazirX, DMM Bitcoin, and a $1.5 billion raid on Bybit in February 2025.
Bitget has engaged SlowMist and Mandiant to investigate the breach. Support has been offered by Binance co-CEO Richard Teng, MEXC CEO Vugar Usi, and Bybit CEO Ben Zhou. Bitget is currently offering a 5 percent bounty to anyone who helps recover or freeze the stolen funds.

