$ techbeacon▋
Phishing

Bitget Blames North Korea-Linked Hackers for $351.6 Million Crypto Heist

Bitget Blames North Korea-Linked Hackers for $351.6 Million Crypto Heist

Cryptocurrency exchange Bitget announced on Tuesday that it believes a group of threat actors with ties to North Korea siphoned roughly $351.6 million from a handful of its hot and warm wallets. The breach, which the platform says was discovered during routine security checks, prompted an immediate freeze on all user withdrawals while the incident is examined.

According to Bitget, the stolen funds were moved through a series of rapid transactions designed to obscure their origin, a technique commonly associated with state‑sponsored hacking outfits that target digital assets. The exchange has not released the exact number of wallets affected, but officials described them as “limited” in scope, suggesting the attackers focused on high‑value balances rather than a broad sweep of user accounts.

Bitget has engaged Mandiant, a cybersecurity firm owned by Google, to lead the forensic investigation. Mandiant’s involvement indicates the seriousness of the attack, as the firm is frequently called upon to trace sophisticated intrusion campaigns linked to nation‑state actors. The investigation will aim to map the flow of the illicit proceeds, identify any compromised private keys, and recommend steps to harden the exchange’s defenses.

The incident arrives at a time when North Korean hacking groups, most notably the Lazarus Group, have intensified campaigns against the cryptocurrency sector. Over the past few years, these actors have been implicated in high‑profile thefts, ranging from the $600 million Ronin Network hack to numerous smaller but cumulative losses across exchanges and DeFi platforms. Their motivation is widely understood to be the circumvention of international sanctions that limit the regime’s access to foreign currency.

Industry observers say the breach underscores the vulnerability of hot wallets—online storage solutions that enable quick transaction processing but are inherently exposed to external attacks. While warm wallets offer a middle ground by balancing accessibility with reduced exposure, both categories still require rigorous multi‑factor authentication, hardware security modules, and continuous monitoring to deter sophisticated adversaries.

Bitget’s response includes not only the temporary suspension of withdrawals but also a promise to reimburse affected users once the investigation clarifies the loss pathways. Regulators in several jurisdictions have previously warned exchanges about the need for robust custodial practices, and this episode may spur tighter oversight. As the crypto community watches the outcome of Mandiant’s probe, the broader lesson remains clear: the intersection of geopolitical conflict and digital finance continues to create high‑stakes risks for both platforms and investors.

Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related