The North Korean Playbook is Public, Yet Exchanges Keep Leaving the Door Unlocked

AI-generated image · US National Wire
Opinion: Bitget's $387.5 million heist is less a surprise and more a symptom of an industry that treats catastrophic security failures as a cost of doing business.
Let’s be clear: this is my opinion, and in my experience covering this space, the cycle of 'shock' following a crypto heist has become a tired performance.
As The Register first reported, the crypto exchange Bitget is currently reeling from a cyberattack that drained approximately $387.5 million in digital assets. Bitget spokesperson Chen is pointing the finger at North Korea, citing "IP behavioral patterns and on-chain signatures" as the evidence. To anyone paying attention, this isn't a revelation; it's a cliché.
As The Register notes, the regime in Pyongyang has a well-documented history of raiding exchanges, including previous hits on DMM Bitcoin, WazirX, and a massive $1.5 billion theft from Bybit in February 2025 that the FBI attributed to North Korea. Yet, here we are again.
The technical details provided by Bitget are particularly damning. Chen identified the breach source as the wallet service's backend system. According to the exchange, hackers breached this system to forge transfer information and trigger the authorization signing process. While Chen claims private key leakage can be ruled out, the fact remains that a "key backend system" was compromised to the point that hundreds of millions of dollars could be spirited away in minutes.
Blockchain intelligence firm Arkham highlighted the sheer velocity of the theft, estimating that $228 million exited Bitget’s wallets in a mere 18-minute window between 18:58 and 19:16 UTC. The haul included $153 million in XRP from a cold wallet, along with $66.2 million in ETH, $34.8 million in USDT, $12.9 million in USDC, and $12.8 million in Tether Gold on Ethereum, with further losses across Base, Avalanche, BNB Smart Chain, Optimism, and Arbitrum.
Bitget is now attempting to project stability. Chen states that user funds are covered 1:1 and points to a User Protection Fund containing over $464 million, as well as more than $1 billion in its own assets. But these assurances are reactive. The exchange has already had to suspend withdrawals for security checks and has hired Mandiant and SlowMist to clean up the mess.
What is most galling is the industry's collective shrug. The Register reports a wave of solidarity from other CEOs: Vugar Usi of MEXC and Richard Teng of Binance both pledged support, while Bybit CEO Ben Zhou noted that Bitget had helped his firm after their own billion-dollar disaster. This "we're all in this together" sentiment is less about strength and more about a shared admission of vulnerability.
There is also the matter of timing. The Register pointed out that the transfers were detected at 18:31 UTC on September 25—the start of the Mid-Autumn Festival holiday in China and a widely celebrated time in Singapore. Bitget has not responded to inquiries about whether the holiday played a role in the attack or the response time.
Bitget is now offering a 5 percent bounty to anyone who can help freeze or recover the funds. It is a desperate move for a company that claims to be a leader in the space. When the playbook for these attacks is this public, and the culprits are this predictable, a $387.5 million loss isn't just a security failure—it's a failure of imagination.

