Cryptocurrency exchange Bitget has confirmed that losses from a recent security breach have grown to $387.5 million, with the company's leadership pointing to North Korea's state-sponsored hackers as the likely culprits behind the sophisticated attack.
How the Attack Unfolded
According to the exchange, the attacker managed to compromise Bitget's systems by fabricating internal transfer requests, tricking the platform into moving funds that appeared to be legitimate. The forged instructions allowed the intruder to siphon assets directly from the company's hot and warm wallets — the connected storage systems exchanges use to process everyday transactions.
The method suggests a deep understanding of Bitget's internal operational procedures rather than a simple external breach. By mimicking authorized transfer protocols, the attacker was able to bypass safeguards designed to catch unauthorized withdrawals.
Faking internal transfer requests let the attacker walk out with nearly $388 million before alarms could stop them.
The scale of the theft places it among the more significant exchange compromises in recent memory, underscoring the persistent vulnerabilities that even large, established platforms face when it comes to wallet security and internal controls.
Why North Korea Is a Suspect
Bitget's CEO has publicly stated that the attack bears the hallmarks of Pyongyang-linked operations. North Korean hacking collectives, most notably the Lazarus Group, have been repeatedly tied to major cryptocurrency heists used to fund the regime's activities.
Investigators often identify these actors through recurring patterns in their tactics, including the way stolen funds are laundered and the technical fingerprints left behind during an intrusion. Those signatures, according to Bitget, align with previous North Korean campaigns.
Key reasons the exchange suspects state-sponsored involvement include:
- The sophistication required to forge internal transfer requests
- Behavioral and technical patterns matching known Lazarus Group activity
- The large scale and rapid execution of the fund extraction
North Korea has become one of the most prolific threats in the crypto space, with security firms attributing billions in stolen digital assets to the country's operatives over the past several years. The Bitget incident, if confirmed, would add to that growing tally and reinforce calls across the industry for stronger internal safeguards.
