Bitget Says Hackers Stole $387.5 Million Through Wallet Backend Breach, Citing North Korea Links

· Original article ↗

Summary

Bitget says hackers exploited a breach in its wallet services backend to steal $387.5 million in cryptocurrency. Withdrawals are suspended as the company investigates with Mandiant and SlowMist and plans to cover losses through its User Protection Fund.

Key points

  • Bitget reported that hackers stole an estimated $387.5 million in cryptocurrency, including ETH, XRP, and USDC.
  • The company said attackers breached a backend system for its wallet services and used vulnerabilities to make unauthorized transfers.
  • Bitget cited IP addresses, behavioral patterns, and on-chain signatures as evidence linking the attack to North Korean-linked groups; blockchain experts also noted links to past Lazarus Group thefts.
  • Withdrawals are suspended while Bitget works with Mandiant and SlowMist on recovery and has notified law enforcement and other platforms.
  • Bitget said its User Protection Fund, valued at more than $464 million, will cover the losses.
  • Some funds connected to attacker wallets have reportedly been frozen, and Bitget announced a recovery bounty for platforms that freeze or help recover funds.

Article Details

Victim Organization
Bitget
Incident Type
Breach of a wallet-services backend enabling unauthorized cryptocurrency transfers and theft
Operational Impact
Bitget suspended withdrawals. Its CEO estimated losses at $387.5 million and said the company would use its User Protection Fund to cover them. Some funds connected to the attackers' wallets have reportedly been frozen.
Claim Status
confirmed

MITRE ATT&CK

Threat Actors

Vendors

Countries

Industries