Bitget’s North Korea-linked $352 million hack could drain 76% of its protection fund

Bitget said its $351.6 million wallet breach bears the hallmarks of North Korean hackers as investigators race to trace and freeze stolen assets.

The crypto exchange said analysis of IP activity and blockchain transactions showed the Sept. 24 attack closely matched techniques used by known North Korean hacking groups. Bitget has reported the incident to relevant authorities and enlisted blockchain security firms Mandiant and SlowMist to investigate, Chief Executive Officer Gracy Chen said.

Onchain analyst Specter separately linked the XRP taken from Bitget to funds stolen during the $24 million AFX hack in July, which was attributed to the TraderTraitor cluster associated with North Korea’s Lazarus Group. The Bitget attribution remains under investigation and has not yet been independently confirmed by its external security firms.

Chart Linking Bitget’s Stolen Funds With North Korea-Linked Attackers (Source: Specter)

The breach affected ETH, XRP, BNB, AVAX, USDT, USDC and other assets across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain and Base. XRP accounted for the largest loss on a single network, Chen said.

Read More:  US Attack on Iran, Global Concern

Bitget said some blockchain foundations have already confirmed freezes of addresses associated with the attacker. Any successful recovery could reduce the final loss from the $351.6 million of assets initially identified as affected.