Bitget Says Hackers Stole $387.5 Million Through Wallet Backend Breach, Citing North Korea Links

Summary
Bitget says hackers exploited a breach in its wallet services backend to steal $387.5 million in cryptocurrency. Withdrawals are suspended as the company investigates with Mandiant and SlowMist and plans to cover losses through its User Protection Fund.
Key points
- Bitget reported that hackers stole an estimated $387.5 million in cryptocurrency, including ETH, XRP, and USDC.
- The company said attackers breached a backend system for its wallet services and used vulnerabilities to make unauthorized transfers.
- Bitget cited IP addresses, behavioral patterns, and on-chain signatures as evidence linking the attack to North Korean-linked groups; blockchain experts also noted links to past Lazarus Group thefts.
- Withdrawals are suspended while Bitget works with Mandiant and SlowMist on recovery and has notified law enforcement and other platforms.
- Bitget said its User Protection Fund, valued at more than $464 million, will cover the losses.
- Some funds connected to attacker wallets have reportedly been frozen, and Bitget announced a recovery bounty for platforms that freeze or help recover funds.
Article Details
- Victim Organization
- Bitget
- Incident Type
- Breach of a wallet-services backend enabling unauthorized cryptocurrency transfers and theft
- Operational Impact
- Bitget suspended withdrawals. Its CEO estimated losses at $387.5 million and said the company would use its User Protection Fund to cover them. Some funds connected to the attackers' wallets have reportedly been frozen.
- Claim Status
- confirmed
MITRE ATT&CK
Threat Actors
Vendors
MandiantThe company has suspended withdrawals, brought in Mandiant and SlowMist, and plans to use its User Protection Fund to cover losses while recovery efforts continue.SlowMistThe company has suspended withdrawals, brought in Mandiant and SlowMist, and plans to use its User Protection Fund to cover losses while recovery efforts continue.