By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Bitget Loses $387M in Hack; North Korea Suspected

Cryptocurrency exchange Bitget reported a significant security breach resulting in the loss of $387.5 million. The attack, which occurred on November 22, 2023, involved an unauthorized actor exploiting internal transfer mechanisms to drain funds from the exchange's hot and warm wallets. Bitget's CEO, Gracy Chen, stated in a post on X (formerly Twitter) that the sophistication and methodology of the hack bear the hallmarks of state-sponsored cybercrime, specifically pointing to North Korea as a probable culprit. The exchange has initiated an investigation and is working with relevant authorities and security firms to trace the stolen assets and apprehend those responsible. Bitget has assured its users that all funds held in their cold wallets remain secure and that the exchange will cover the losses incurred by users due to this incident, demonstrating a commitment to user protection despite the substantial financial impact.
The modus operandi described by Bitget involved the attacker impersonating internal transfer requests, a tactic that suggests a deep understanding of the exchange's operational procedures or successful social engineering. This method allowed the perpetrator to move funds from Bitget's operational wallets, which are typically connected to the internet for trading and withdrawals, into their own control. The distinction between hot and warm wallets is crucial; hot wallets are online and readily accessible for immediate transactions, while warm wallets are semi-online, offering a balance between accessibility and security. The fact that both were compromised indicates a significant breach of the exchange's internal security protocols.
North Korea has been widely implicated in numerous cryptocurrency heists in recent years, with various cybersecurity firms and international bodies attributing these attacks to groups like Lazarus, which are believed to be state-sponsored. These groups have been known to target cryptocurrency exchanges and decentralized finance (DeFi) platforms to fund the country's nuclear weapons program and evade international sanctions. The estimated total value of cryptocurrency stolen by North Korean-linked actors has reached billions of dollars, making them one of the most prolific cybercriminal entities in the digital asset space. The specific technical details of the Bitget hack, as described by Chen, align with patterns observed in previous attacks attributed to these North Korean entities, including the use of sophisticated social engineering and exploitation of internal transfer systems.
In response to the incident, Bitget has temporarily suspended all withdrawals and deposits to conduct a thorough security audit and implement enhanced protective measures. The exchange has also committed to providing full transparency regarding the investigation and its findings. This event underscores the persistent and evolving threats faced by cryptocurrency exchanges and the broader digital asset ecosystem. The ability of attackers to compromise internal systems, rather than solely relying on external vulnerabilities, highlights the critical importance of robust internal controls, employee training, and continuous security monitoring. Bitget's commitment to covering user losses is a significant step in maintaining customer trust following such a severe security event, though the long-term implications for the exchange's reputation and operational resilience remain to be seen.
Original source — read the full reporting at the publisher:
Read on DecryptGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.