Cointelegraph
DOGE$0.09517 0.78%
TRX$0.3386 1.39%
LINK$13.40 8.05%
ZEC$1,543.61 1.31%
ADA$0.2485 3.15%
XRP$1.53 1.70%
ETH$2,679.63 0.30%
BTC$84,175.10 0.04%
XMR$568.46 1.79%
BNB$775.11 0.40%
XLM$0.2197 8.20%
SOL$116.54 1.29%
HYPE$91.91 0.95%
Written by Felix Ngstaff editorReviewed by Yohan Yunstaff editor

Bitget CEO suspects North Korea behind $352M hack, citing IP clues

Latest NewsPublishedSep 25, 2026

Bitget CEO Gracy Chen said a preliminary investigation found IP addresses matching VPN choices associated with a DPRK hacking group.

Update (Sept. 25 at 4:30 am UTC): This article has been updated to add new comments from Bitget CEO Gracy Chen and preliminary analysis from onchain researcher Specter.

Bitget CEO Gracy Chen said North Korean hackers may be behind the exchange’s $351.6 million security breach on Thursday, citing preliminary findings linking IP addresses to VPN services used by a North Korean group. 

Speaking during a live Q&A following the incident on X, Chen said security investigators had flagged similarities with previous North Korean attacks. She said the exchange did not believe the breach was an inside job. 

“We’ve identified some IP addresses that match the VPN choices by a certain DPRK group,” Chen said, referring to the Democratic People’s Republic of Korea.

North Korean hackers were linked to an estimated $2.02 billion in crypto theft in 2025, including the roughly $1.5 billion Bybit exchange hack, which the FBI attributed to North Korea. 

Bitget CEO Gracy Chen hosts a live broadcast on X hours after the hack. Source: Bitget

“The pattern looks very much like what the North Korean team did before,” she said.

An onchain researcher has also independently alleged a link between the Bitget theft and a North Korean hacking collective.

In a post on X, Specter said they traced some of the stolen XRP to an Ethereum address that received 68,808 USDT from a wallet. That same wallet had once sent Ethereum to an address labeled “AFX EXPLOITER.”

AFX, which was hacked for $24 million in July, said in its postmortem that it suspected involvement by TraderTraitor, a North Korea-linked group.

Source: Specter

Chen later said on X that hackers breached a backend system of the wallet service and exploited it to forge transfer information, invoking the authorization signing process.

“They did not forge user withdrawal requests, nor did they obtain our private keys of the cold wallet and any hot, warm wallet,” she said during the Q&A.

Chen said investigators were still determining which systems were compromised and how the attackers gained access.

Related: Bitget confirms $352M security breach, suspends withdrawals

The comments come after Bitget reported unauthorized transfers affecting portions of its hot and warm wallet infrastructure on Thursday. Withdrawals remain suspended at the time of publication.

During the Q&A, Chen also said some stolen funds had been recovered, without specifying an amount. She said the exchange was working with blockchain foundations and other partners on recovery efforts.

Magazine: Asia dominates Crypto Adoption Index, Bitget’s $351M hack: Asia Express

1 minute letter

Subscribe to daily byte-sized crypto news from Cointelegraph

Subscribe
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

More on the subject