
Source: specter
Bitget CEO Gracy Chen went on X just hours after the exchange lost $351.6 million, telling users it was “very likely” a North Korean operation.
The evidence she pointed to IP addresses matching VPN infrastructure previously linked to a DPRK group is real. But that’s also a fairly low bar for attribution, and exchanges have made similar calls before without investigators ever confirming who was actually behind an attack. At the time Chen made the claim, no government agency had publicly attributed the breach to North Korea, and investigators were still trying to establish exactly which systems had been compromised.
The attackers didn't steal private keys from Bitget’s hot, warm or cold wallets, and they didn't fake a user withdrawal request. They got into a backend system, manipulated the transaction data and then used that altered information to get Bitget’s own authorization process to approve the transfers as legitimate.
That looks a lot like what happened with WazirX in 2024. In that case, hackers went after the multisig contract itself rather than just stealing the keys. The pattern is worth watching. As exchanges make key theft harder, compromising the systems that sit around those keys becomes an increasingly attractive way in.
On-chain, Two Bitget wallets sent nearly 103 million XRP to the same address across three transactions. By the following day, only about 0.4% of the stolen funds had moved out of the attackers’ wallets. The rest was still sitting there, visible to anyone tracking the addresses.
The strongest push for the North Korea theory didn't actually come from Bitget. It came from an independent researcher known as Specter, who posted on X: “I present to you THE LAZARUS GROUP,” and linked the Bitget funds to July’s $24 million AFX hack through a trail involving NEAR Intents. But that connection relies on a chain of addresses that researchers have linked by inference, not an official attribution. Bitget itself hasn't confirmed the connection.
There’s one other detail worth keeping in mind. Chen said she had personally lost around $80,000 to the same alleged group in an earlier incident that had nothing to do with Bitget. That experience may explain why she was quick to suspect the Lazarus Group here, but it doesn't establish who carried out this attack.
During a Q&A session, Chen also said some stolen funds had been recovered, without specifying any amount. She said the exchange was working with blockchain foundations and other partners on recovery efforts.