Bitget CEO Points to North Korea in $352M Exchange Hack
Bitget's CEO says preliminary IP evidence links the $352M breach to a North Korean hacking group, raising fresh alarm about state-sponsored crypto theft.
The $352 million hack of cryptocurrency exchange Bitget is drawing scrutiny toward North Korea, with CEO Gracy Chen publicly stating that early forensic work uncovered IP address patterns consistent with VPN infrastructure previously associated with DPRK-linked hacking operations. While the investigation remains ongoing and no definitive attribution has been made, the disclosure marks one of the most direct executive-level accusations following a major crypto breach in recent memory.
North Korean state-sponsored hackers have become a persistent and sophisticated threat to the digital asset industry. Groups such as Lazarus have been linked by U.S. authorities and blockchain analytics firms to billions of dollars in stolen cryptocurrency over the past several years, with proceeds believed to fund the regime's weapons programs. The VPN-based obfuscation technique Chen referenced aligns with known operational patterns these groups use to mask geographic origins.
Read more Deere Stock Trades Near Fair Value as Business Mix Shifts →
The significance of IP-based attribution should be weighed carefully. VPN trails can be deliberately planted or recycled by unrelated actors, and intelligence-grade confirmation typically requires coordination with government agencies and multiple corroborating data points. That said, exchanges and blockchain security researchers have grown increasingly skilled at clustering behavioral fingerprints — transaction timing, mixer usage, and infrastructure signatures — that make attribution more credible over time.
For the broader crypto industry, the Bitget incident underscores a structural vulnerability: centralized exchanges remain high-value, high-concentration targets. A single successful intrusion can yield state-level adversaries a nine-figure payday that would be far harder to extract from decentralized protocols. Regulators in the U.S. and abroad have been pressing exchanges to tighten custody and operational security standards, and incidents of this scale tend to accelerate that policy pressure.
Continue reading at Cointelegraph.