BNB $774.04 -0.35%
XRP $1.58 +5.50%
ETH $2,694.19 +1.02%
BTC $83,942.83 -0.24%
BNB $774.04 -0.35%
XRP $1.58 +5.50%
ETH $2,694.19 +1.02%
BTC $83,942.83 -0.24%
BREAKING
Digital Wallet

Bitget Suffers $352 Million Hack Linked to North Korea’s Lazarus Group

Bitget's $352 Million Lazarus Group Breach Hits During 8th Anniversary
Bitget's $352 Million Lazarus Group Breach Hits During 8th Anniversary

Community Trust ScoreVerified

96%
Real
Verified23 votes
Updated 2 hours ago

Bitget got hit hard. The exchange confirmed a $352 million hack tied to North Korea’s Lazarus Group, with both hot wallets and warm wallet layers compromised in what looks like one of the more sophisticated exchange breaches in recent memory.

Leading crypto investigator Specter Analyst was first to link the attack to Lazarus. Bitget CEO Gracy Chen backed that up during a livestream, saying the attack’s characteristics line up with previous Lazarus tactics. She was pretty direct about it: the breach wasn’t a private key compromise. What actually happened was more targeted — hackers got into Bitget’s wallet services backend, manipulated transfer data, forged signing processes, and pushed through unauthorized transactions that way. The cold wallets stayed safe. The hot and warm wallet layers didn’t. Chen also clarified that Bitget’s standalone wallet product, which runs separately from the exchange itself, wasn’t touched.

The initial loss estimate was lower. It wasn’t.

Advertisement

How the Attack Actually Worked

The attackers didn’t brute-force their way through a private key. That’s the part worth paying attention to. They went after the backend of Bitget’s wallet services infrastructure, which let them manipulate transfer details and authorize their own signing processes without triggering the standard security checks. It’s a more surgical approach than what most people picture when they hear “crypto hack,” and it’s basically the kind of method Lazarus has refined over years of targeting exchanges, bridges, and custodial platforms.

Chen said during the livestream that multiple blockchain networks moved quickly to freeze addresses connected to the stolen funds. That’s a meaningful step — it limits how fast the attackers can move or cash out what they took. Whether it’s enough to recover a meaningful portion of $352 million is a different question, and no one’s giving a clear answer on that yet.

Bitget pulled withdrawals offline. That’s still in place. The exchange is working with independent cybersecurity firms Mandiant and SlowMist to dig into exactly how the breach happened and what needs to change before normal operations come back. No timeline has been given publicly for when withdrawals resume.

User Funds and the Protection Fund

Chen assured users their money isn’t gone. Bitget’s User Protection Fund, which holds over $464 million, will cover the majority of the losses. That’s the fund the exchange has built up specifically for situations like this — it’s bigger than the hack, which matters for user confidence even if the optics of a $352 million breach are rough regardless.

The hack landed right as Bitget was marking its eighth anniversary. Not great timing. What was supposed to be a milestone moment for the exchange turned into a crisis communications exercise, with Chen doing a livestream to walk users through what happened instead of celebrating the anniversary. The losses were also underestimated at first, which compounded things — finding out the real number was higher than initially thought didn’t help the exchange’s credibility in the early hours of the news cycle.

Bitget says it’s working with law enforcement alongside the cybersecurity firms. The collaboration with Mandiant and SlowMist is meant to get a full picture of the breach — not just patch the immediate hole, but understand the attack chain well enough to prevent a repeat. SlowMist has a track record in on-chain forensics across Asian exchanges. Mandiant brings a different kind of institutional depth. Using both probably makes sense given the scale.

What Bitget Is Doing Right Now

The exchange froze the affected addresses fast. Multiple blockchain networks cooperated on that, which is worth noting — coordinated freezes across chains are harder to pull off than they sound, and the speed of that response probably limited some of the damage. Bitget is also under pressure to show its security architecture has been fundamentally tightened, not just patched.

The warm wallet layer is an interesting detail here. Most exchange security conversations focus on hot versus cold wallets, but warm wallets — which sit somewhere between the two in terms of accessibility and exposure — are increasingly where sophisticated attackers look for gaps. Lazarus has shown a pattern of targeting exactly these kinds of intermediate layers, where transaction signing happens frequently enough to create exploitable windows.

User trust is the harder thing to rebuild. The money side is largely covered by the protection fund. But an exchange that just had $352 million walk out the door through its backend has a credibility problem that $464 million in reserves doesn’t fully fix on its own. The investigation’s findings, and what Bitget actually changes as a result, will probably matter more long-term than the fund coverage.

No further comments on a service restoration timeline have come from the exchange. Investigations are ongoing. Bitget’s collaboration with Mandiant and SlowMist continues, with the exchange saying it’s prioritizing platform security and user fund protection above getting withdrawals back online.

Frequently Asked Questions

Who carried out the Bitget hack?

The hack has been linked to North Korea’s Lazarus Group, with crypto investigator Specter Analyst making the initial attribution and Bitget CEO Gracy Chen confirming the attack’s methods align with known Lazarus tactics.

Will Bitget users get their money back after the hack?

Bitget’s CEO Gracy Chen said the exchange’s User Protection Fund, which holds over $464 million, will cover the majority of the $352 million in losses.

Why It Matters

This breach underscores the ongoing vulnerability of cryptocurrency exchanges to sophisticated cyberattacks, particularly those linked to state-sponsored groups like Lazarus. As the crypto market matures, incidents like this can erode user trust and lead to increased regulatory scrutiny, potentially reshaping security protocols across the industry. The timing of the attack, coinciding with Bitget's anniversary, may further amplify concerns among investors regarding the resilience of exchange security measures in an increasingly hostile digital landscape.

Community Trust IndexHigh Confidence
96%
Real
Real96%4%Fake
23 community signals

Evie Vavasseur

Evie Vavasseur is a crypto writer and digital content specialist covering the latest developments in blockchain technology, decentralized finance, and the broader digital asset ecosystem. With a keen eye for emerging trends, Evie provides accessible and insightful coverage of cryptocurrency markets, NFTs, and Web3 innovations for The Currency Analytics.

Advertisement

Related Stories