Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Crypto News Exchanges

    Bitget CEO Says North Korea Likely Behind $352M Hack via IP Clues

    13 seconds ago
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    Bitget Ceo Says North Korea Likely Behind $352m Hack Via Ip Clues
    Bitget Ceo Says North Korea Likely Behind $352m Hack Via Ip Clues

    Bitget’s CEO Gracy Chen said preliminary investigation points to North Korean hackers behind the exchange’s reported $351.6 million security breach on Thursday. Speaking during a live Q&A on X shortly after the incident, Chen said investigators identified IP addresses they believe align with VPN services used by a DPRK-linked group.

    Chen also said Bitget does not believe the breach involved an insider. She added that investigators were still mapping which parts of the exchange’s infrastructure were compromised and how the attackers gained access.

    Key takeaways

    • Bitget CEO Gracy Chen said preliminary findings link the attack to IP addresses associated with VPN choices used by a DPRK group.
    • Chen said the exchange does not think the incident was carried out by an insider.
    • Bitget indicated hackers moved funds directly, rather than forging user withdrawal requests.
    • Withdrawals remained suspended at the time of publication, while Bitget works with partners on recovery efforts.

    CEO points to VPN-linked IP addresses

    In the Q&A, Chen told viewers that security investigators had flagged similarities between this incident and past DPRK-linked activity. She specifically referred to “some IP addresses” that match the VPN services reportedly used by the group.

    Chen’s remarks described the attribution as preliminary, framed around technical indicators rather than a final, court-grade conclusion. Still, her comments reinforce a broader pattern the crypto industry has seen across multiple high-profile incidents, where infrastructure-level traces and operational “fingerprints” are used to connect attacks to specific threat actors.

    Chen also said the investigation is ongoing, including efforts to determine which systems were affected and the precise entry point attackers used. That matters for users and market participants because identifying the initial access vector typically influences what remedial actions are prioritized—such as credential resets, segmentation changes, or controls around administrative interfaces.

    How the breach reportedly worked

    Beyond attribution, Chen offered details about the mechanics of the theft. She said hackers breached Bitget’s systems and transferred funds directly instead of forging user withdrawal instructions.

    According to Chen, attackers “did not forge user withdrawal requests,” and she said they did not obtain Bitget’s private keys for any cold wallet or hot/warm wallet. Those distinctions are important because they suggest the compromise may not have relied on the same controls-behavior that some other incidents have shown, even if the ultimate outcome—unauthorized transfers—was severe.

    Chen said investigators were still determining which systems were compromised. Until that scope is clear, it remains difficult for external observers to assess whether this was limited to particular services (for example, withdrawal-related infrastructure) or whether the breach potentially affected other operational components. For users, that uncertainty is reflected in the exchange’s decision at the time of publication to keep withdrawals suspended.

    Bitget’s reported unauthorized transfers affected portions of its hot and warm wallet infrastructure, according to the exchange’s earlier disclosures. Withdrawals were still suspended at the time the CEO’s comments were reported.

    Recovery efforts underway, but amounts not disclosed

    During the Q&A, Chen said that some of the stolen funds had been recovered. She did not provide an amount, but said Bitget is working with blockchain foundations and other partners on recovery efforts.

    Without a disclosed figure, observers will likely focus on whether recovery is partial or extensive—and, crucially, whether the attackers’ remaining funds are successfully identified and potentially blocked or reclaimed. The effectiveness of these efforts can vary significantly depending on factors such as how quickly assets are frozen, how the funds are routed through intermediaries, and whether counterparties and analytics teams are engaged promptly.

    The broader market context also matters. If attribution strengthens—especially when aligned with prior patterns linked to DPRK-associated groups—it may influence how institutions assess counterparty risk and how exchanges harden controls related to suspicious network behavior and wallet-operation workflows.

    DPRK links follow a pattern of major thefts

    Chen’s comments come amid a long-running attribution debate in the crypto space, where North Korea-linked groups have frequently been referenced in connection with large-scale cyber thefts and laundering activity.

    In earlier reporting, Cointelegraph described an estimated $2.02 billion in crypto theft attributed to North Korean actors in 2025, including a roughly $1.5 billion Bybit hack that the FBI attributed to North Korea. Cointelegraph also linked those broader estimates to “South Korea gets rich from crypto” reporting that framed North Korean activity in the context of weapons-related incentives.

    Chen’s statement that the “pattern looks very much like what the North Korean team did before” suggests Bitget is interpreting technical and behavioral indicators through that existing lens. However, the exchange’s own caveat—she described findings as preliminary and said investigators were still working out the full compromise path—means readers should expect updates as more information becomes available.

    For investors and traders, the immediate concern is not only the size of the breach, but the robustness of the exchange’s controls and the completeness of remediation. For builders and security teams, the incident underscores a recurring theme: even when private keys remain uncompromised, attackers may still succeed by compromising operational systems that can authorize or execute transfers.

    Next, the key developments to watch are Bitget’s investigation findings on exactly which systems were breached, whether the exchange expands its recovery estimate beyond “some” funds, and when—if at all—withdrawals resume after the affected hot/warm infrastructure is stabilized.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Bitget Reports $352m Security Breach, Halts Withdrawals

    Bitget Reports $352M Security Breach, Halts Withdrawals

    1 hour ago
    Bitget Ceo Says $352m Hack May Involve North Korea, Citing Ip Clues

    Bitget CEO Says $352M Hack May Involve North Korea, Citing IP Clues

    2 hours ago
    Asia Leads Crypto Adoption Index As Bitget Faces $351m Hack Risk

    Asia Leads Crypto Adoption Index as Bitget Faces $351M Hack Risk

    3 hours ago
    Blackrock Expands Tokenization Push With Ondo Finance Partnership

    BlackRock Expands Tokenization Push With Ondo Finance Partnership

    3 hours ago
    Fed Proposes New Capital And Redemption Rules For Stablecoin Issuers

    Fed Proposes New Capital and Redemption Rules for Stablecoin Issuers

    4 hours ago
    Doublezero Adds Dedicated Fiber Market Data For Hyperliquid Traders

    DoubleZero Adds Dedicated Fiber Market Data for Hyperliquid Traders

    5 hours ago

    Search Crypto News

    Featured Crypto News

    Exclusive Abu Dhabi F1 Hospitality Experience Now Available For Crypto Executives, Investors And Vip Guests

    Exclusive Abu Dhabi F1 Hospitality Experience Now Available for Crypto Executives, Investors and VIP Guests

    7 September 2026

    Latest News

    • Bitget CEO Says North Korea Likely Behind $352M Hack via IP Clues
    • Bitget Reports $352M Security Breach, Halts Withdrawals
    • Bitget CEO Says $352M Hack May Involve North Korea, Citing IP Clues
    • Asia Leads Crypto Adoption Index as Bitget Faces $351M Hack Risk
    • BlackRock Expands Tokenization Push With Ondo Finance Partnership
    • Fed Proposes New Capital and Redemption Rules for Stablecoin Issuers
    • DoubleZero Adds Dedicated Fiber Market Data for Hyperliquid Traders
    • Bitcoin Holds Steady as ONDO Gains Amid US Treasury Yield Surge
    • Strive Outpaces Saylor’s Strategy With $86 Million Bitcoin Treasury Push
    • Crypto Treasury Model Weakens as DAT Premiums Decline, DWF Notes

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    Ledger

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    📞 +971 50 449 2025
    ✉️ info@cryptobreaking.com
    📍Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    Bitpanda
    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!