Published on

North Korean hackers are suspected of stealing $387.5 million (€332.8mn) in cryptocurrency from major global cryptocurrency exchange Bitget in what appears to be the biggest crypto theft of the year.

In a statement, Bitget said it detected unauthorised transfers from some of its hot and warm wallets on Thursday.

Hot wallets are connected to the internet so an exchange can process transactions quickly, while warm wallets have more limited online access.

The company said its cold wallets, which are kept more isolated, were not affected.

The company identified IP addresses whose VPN usage appeared to match that of a North Korean group, making a North Korean connection “very likely,” CEO Gracy Chen said in a livestream.

“We’ve identified IP addresses that match the VPN choices by a certain [Democratic People’s Republic of Korea] DPRK group. We think this is very likely to be attacked by North Korea,” Chen said in a post on X.

The attackers did not obtain the private keys used to access Bitget’s hot, warm or cold wallets, Chen added, meaning they could not use those keys to take direct control of the wallets.

Instead, the hackers breached an internal system and entered false transaction information that made fraudulent transfers appear legitimate to Bitget’s approval system.

Bitget says its user protection fund, which it said held more than $464 million (€398.5mn) at the time of the attack, is sufficient to cover the loss.

The customer account balances remain accurate, while deposits and trading have continued to operate.

However, Bitget temporarily suspended withdrawals as a precaution while it checked its systems. It has announced plans to restore withdrawals in stages from 28 September.

The company said it had notified law enforcement and was working with security firms to investigate the attack and trace the stolen funds.

Chen said in a livestream on Friday that people she identified as members of Lazarus, a North Korean state-linked hacking group known for stealing cryptocurrency, had previously approached her by posing as a journalist to arrange a Zoom interview.

This is the largest cryptocurrency theft reported so far this year, according to a report from the blockchain intelligence firm TRM Labs.

Stolen assets are used to fund nuclear weapons and missiles

North Korea has previously been identified as responsible for large-scale virtual asset thefts.

Money stolen by North Korean state-linked hackers helps fund the country’s nuclear weapons and ballistic missile programmes, according to the United States (US) Treasury Department.

According to another report from TRM Labs, North Korean groups accounted for 76% of the value stolen in cryptocurrency hacks through April this year. The figure predates the Bitget incident.

In February 2025, North Korean hackers stole approximately $1.5 billion (€1.28bn) in virtual assets from cryptocurrency exchange Bybit, according to the US Federal Bureau of Investigation (FBI).

The FBI said the hackers made the funds harder to track by rapidly converting some of the stolen assets into other cryptocurrencies and distributing them across thousands of addresses.

While North Korea has developed sophisticated cyber capabilities, its government severely restricts ordinary citizens’ access to the global internet.

According to the United Nations Human Rights Office Seoul in South Korea, most citizens can use only a controlled domestic network.

Share.
Exit mobile version