Bitget's CEO, Gracy Chen, has suggested that North Korean hackers may be responsible for the exchange's recent security breach, which resulted in a loss of $351.6 million. Preliminary investigations have identified IP addresses linked to VPN services used by a known DPRK hacking group.
During a live Q&A session following the incident, Chen emphasized that the breach did not appear to be an inside job. She noted that the attack bore similarities to previous incidents attributed to North Korean cybercriminals.
Chen stated, “We’ve identified some IP addresses that match the VPN choices by a certain DPRK group,” highlighting the ongoing investigation into how the attackers gained access to Bitget's systems.
Unlike previous hacks, the attackers did not forge user withdrawal requests or gain access to the exchange's private keys, which has raised questions about the methods used in this breach. Chen mentioned that some stolen funds had been recovered, although she did not disclose the amount.
As a precaution, Bitget has suspended withdrawals while it works with blockchain foundations and partners to recover the stolen assets. The investigation into the compromised systems is ongoing, and further updates are expected.