Bitget breach North Korea claim: Crypto exchange Bitget says about $387.5 million in digital assets was sent to attacker-controlled addresses during a security incident it identified on September 24. Chief executive Gracy Chen has said the evidence points to North Korean-connected hacking groups, but the company’s detailed incident update does not name North Korea, Lazarus Group or another suspected actor.
That distinction is doing real work. Bitget has confirmed its account of the transfers and its response. The attribution is Chen’s allegation, reported by The Record, rather than an independently confirmed finding in the material available.
In a September 25 update, Bitget said its on-chain tracing and transaction classification raised its assessed loss from $351.6 million to roughly $387.5 million. The company said the added amount reflected Zcash and TRON assets omitted from the earlier accounting, rather than additional unauthorized transfers.
Did Bitget link its breach to North Korea?
Chen told a Bitget town hall that IP addresses, behavioral patterns and on-chain signatures connected the incident to North Korean-linked groups, according to The Record. The publication also reported that blockchain analysts identified connections to earlier thefts attributed to Lazarus Group.
Neither account amounts to a public, independent technical attribution by law enforcement or a security firm. Bitget’s own September 25 update describes the attack path, controls bypassed and remediation work, but makes no public allegation naming North Korea or Lazarus.
What does Bitget say happened?
Bitget said an attacker exploited a vulnerability in its wallet-services backend, enabling unauthorized transfers. The company said it had found and fixed the underlying flaw, contained the incident, and believed no further unauthorized transfers were possible. Those are Bitget’s statements; the supplied reporting does not provide an independent technical validation.
The exchange said the affected assets spanned Ethereum and other EVM networks, XRP Ledger, Zcash and TRON. It listed XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX among the assets affected.
Bitget said withdrawals remained unavailable while it completed security checks and prepared to restore them. It said Mandiant and SlowMist were assisting its investigation and that some assets had been frozen with industry partners’ help. The company said it expected to announce withdrawal status or timing by September 26 at 4 a.m. UTC. The supplied reporting did not give a timetable for restoring withdrawals or quantify recovered funds.
How does Bitget’s recovery bounty work?
Bitget has offered a recovery bounty for voluntary efforts that directly result in assets being frozen or recovered. Under the program, eligible contributors may receive 5% of funds successfully frozen and 5% of funds successfully recovered.
The offer has limits. Bitget says activity taken under court orders, law-enforcement requests or other legal processes does not qualify, and the company retains final say over eligibility, calculations and payouts. A listed bounty is not confirmation that assets will be returned.
This story draws on original reporting from The Record.