Build with CoinStats’ all-in-one API. Learn more

EnglishDeutsch한국어中文EspañolFrançaisՀայերենNederlandsРусскийItalianoPortuguêsTürkçeポートフォリオトラッカー暗号通貨料金Crypto APIMCP統合ニュースRWA市場獲得するブログNFTウィジェットDeFiポートフォリオトラッカーデリバティブETF Flowsクリプトゲーミング24時間のレポートプレスキットAPI文書

Bitget hack exposed nearly $160M in XRP as North Korea link probed

3時 前•
強気相場:

0

弱気相場:

0

Bitget CEO suspects North Korean involvement in the recent $351M hack. During a live Q&A session on X, CEO Gracy Chen announced that the attack ties back to VPNs frequently used by North Korean state-sponsored groups. She noted that investigators flagged patterns matching previous North Korean cyberattacks.

“We’ve identified some IP addresses that match the VPN choices by a certain DPRK group. […]The pattern looks very much like what the North Korean team did before,” Chen said.

XRP accounted for the largest share of the stolen funds at about $157.5 million, followed by ETH at $85.8 million. USDT, USDC, USDT0, XAUt, BNB, AVAX, and TRX made up the remainder.

In the past few months, North Korean hackers have been actively linked to a number of stolen funds. For instance, over the course of last year, state-sponsored cybercriminals from North Korea were tied to a staggering $2.02 billion in digital asset thefts, and for the first half of this year, $600 million in cryptocurrency.

Bitget’s hack involved transfers of multiple assets like Ether and XRP

Bitget quickly took measures after identifying suspicious fund transfers on Thursday. It immediately suspended withdrawals and alerted law enforcement and security firms. At the time, Chen, the company’s CEO, nonetheless reassured users that the hack compromised only a portion of the exchange’s online wallets, while its cold wallets remained secure. 

“User funds are safe. The full amount of this loss falls within the coverage of Bitget’s User Protection Fund, which currently holds over $464 million,” she asserted. 

During the latest Q&A, Chen also provided more information regarding the hack. She mentioned that the hack happened due to a direct system breach. As such, the hackers did not use any of the customers’ withdrawal channels.

However, she claimed that they have yet to identify all the affected servers and understand fully how the attackers got past their defenses. Additionally, she revealed that the exchange has recovered some of the stolen funds. According to Chen, they are in the process of recovering the remaining amount in collaboration with blockchain foundations and industry security partners.

At the moment, user withdrawals are still suspended for security reasons.

WaterPlum Group targeted about 30000 devices and over 7000 wallets

One of North Korea’s many hacker groups, WaterPlum, has reportedly breached tens of thousands of devices. In their global attack campaign, they managed to compromise 7,000 crypto wallets across over 100 nations. 

According to reports from the FBI, Japan’s National Police Agency, Australia’s ACSC, and Germany’s BND and BfV, criminal activity was reported between December 2025 and July 2026, during which they routed over $10.7 million (JPY 1.7 billion) in digital assets to Pyongyang.

The attackers would masquerade themselves as recruiters and executives in AI, crypto, and NFT, among other fields. During fake tech interviews, job seekers were asked to download sample assignments. Hidden within the project dependencies were trojans such as StoatWaffle, OtterCookie, and BeaverTail waiting to execute.

The Bitget breach also follows other major crypto attacks linked to North Korean hackers. In February 2025, Bybit lost roughly $1.5 billion in cryptocurrency in one of the industry’s largest hacks. Blockchain investigators attributed the attack to the Lazarus Group, a North Korean state-linked hacking operation. The incident demonstrated how quickly attackers can move and obscure stolen cryptocurrency across multiple wallets.

Following the Bitget incident, Bybit CEO Ben Zhou said the exchange would assist Bitget with tracing and recovering the stolen cryptocurrency. The cooperation builds on previous support between the two exchanges, with Bitget having assisted Bybit following its own security breach.

TRM Labs analysis shows that North Korea attacks target mostly back-end infrastructure

More recently, blockchain forensics firm TRM Labs has pointed out that sophisticated threats, such as DPRK attacks, systematically target backend infrastructure rather than source code. The highest-risk areas for any digital asset firm lie in key management, cryptographic signing setups, and multi-layered approval processes.

The firm advised crypto platforms to focus their security budgets on the specific infrastructure vulnerabilities that have historically triggered the most devastating financial collapses.

“Incident response planning, insurance coverage, and treasury reserves should also be designed around the possibility of a major infrastructure compromise rather than an average loss. A single successful attack continues to define annual losses across the industry,” the firm stated.

The incident also highlights the growing security risks facing centralized crypto exchanges, which remain attractive targets because they hold large amounts of digital assets in infrastructure that can become a single point of failure.

Even when customer-facing withdrawal systems remain untouched, a compromise of backend systems or signing infrastructure can expose significant funds.

The Bitget investigation could therefore provide further insight into how exchanges can strengthen wallet controls, transaction approvals, server security, and monitoring systems against increasingly sophisticated attacks.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.

3時 前•
強気相場:

0

弱気相場:

0

すべての暗号通貨、NFT、DeFiを1か所から管理

開始に使用しているポートフォリオを安全に接続します。