Bitget CEO Gracy Chen has pointed to North Korean state-sponsored hackers as the likely culprits behind a $352 million exploit, citing early forensic evidence that traces the attack to IP patterns commonly linked to the country's cyber operations.
Tracing the Attack
According to Chen, a preliminary investigation uncovered IP addresses tied to VPN configurations that align with those historically used by a hacking group operating out of the Democratic People's Republic of Korea. The digital fingerprints, she said, offered an early indication of who may have been behind the massive theft.
While the findings remain preliminary, the executive framed the IP clues as a meaningful lead pointing toward one of the most notorious actors in the crypto crime landscape. North Korean groups have repeatedly been accused of targeting exchanges and blockchain platforms to fund state activities.
The digital trail left behind may prove harder to erase than the funds themselves.
A Familiar Pattern
North Korea-linked hackers have become a recurring threat across the cryptocurrency industry, blamed for some of the largest thefts in recent memory. Investigators frequently rely on a combination of on-chain analysis, IP data, and behavioral signatures to attribute such breaches.
The scale of the reported $352 million loss underscores the persistent security challenges facing exchanges and their users. High-value platforms remain prime targets for sophisticated, well-resourced attackers seeking to launder stolen assets quickly.
Key elements cited in the early probe include:
- IP addresses matching known VPN choices
- Tactics consistent with a DPRK-associated hacking group
- Ongoing forensic analysis to confirm attribution
Chen indicated that the investigation is still unfolding, and further details are expected as analysts continue tracing the movement of the stolen funds and firming up their conclusions about the source of the breach.
