Bitget CEO links $352m breach to North Korean hackers
Gracy Chen says investigators found IP addresses matching VPN services used by a North Korean group, as withdrawals stay suspended after the exchange's $351.6m loss.

Key points
- Bitget CEO Gracy Chen said preliminary findings link IP addresses to VPN choices associated with a DPRK hacking group.
- The breach involved $351.6 million in unauthorised transfers from hot and warm wallet infrastructure.
- Chen said the exchange does not believe the incident was an inside job.
- Onchain researcher Specter traced stolen XRP to an address that received 68,808 USDT from a wallet previously linked to an address labelled AFX EXPLOITER.
- Chen said some stolen funds have been recovered, without giving an amount, and withdrawals remain suspended.
Bitget chief executive Gracy Chen has said North Korean hackers may be behind the exchange's $351.6 million security breach, citing preliminary findings that link IP addresses to VPN services used by a North Korean group. She spoke during a live question and answer session on X after the incident. Chen said the exchange did not believe the breach was an inside job.
According to CoinTelegraph, Chen said security investigators had flagged similarities with earlier North Korean attacks. She said some IP addresses matched the VPN choices of a certain DPRK group, referring to the Democratic People's Republic of Korea. She added that the pattern looked very much like what the North Korean team had done before.
The article notes that North Korean hackers have been linked to an estimated $2.02 billion in crypto theft in 2025. That figure includes the roughly $1.5 billion Bybit exchange hack, which the FBI attributed to North Korea. The Bitget breach is the latest in a series of large exchange incidents this year.
IP clues point to DPRK
An onchain researcher has also independently alleged a link between the Bitget theft and a North Korean hacking collective. In a post on X, Specter said they traced some of the stolen XRP to an Ethereum address that received 68,808 USDT from a wallet. That same wallet had once sent Ethereum to an address labelled AFX EXPLOITER. AFX, hacked for $24 million in July, said in its postmortem that it suspected involvement by TraderTraitor, a North Korea-linked group.
Chen later said on X that hackers breached a backend system of the wallet service and exploited it to forge transfer information, invoking the authorisation signing process. She said they did not forge user withdrawal requests, and did not obtain private keys for the cold wallet or any hot or warm wallet. Investigators were still working out which systems were compromised and how the attackers gained access.
The comments follow Bitget's report of unauthorised transfers affecting parts of its hot and warm wallet infrastructure on Thursday. Withdrawals remained suspended at the time of publication. During the Q&A, Chen said some stolen funds had been recovered, without specifying an amount, and that the exchange was working with blockchain foundations and other partners on recovery efforts.
Onchain researcher alleges link
The case matters because attribution to North Korean groups has become a recurring theme in crypto security. If confirmed, the Bitget incident would add to a growing tally of losses tied to state-linked actors. For users, the immediate concern is the suspension of withdrawals and the exchange's ability to trace and return the missing funds.