Bitget CEO says preliminary clues point to suspected North Korean hackers; attribution of 351.6 million USD attack remains under investigation
BIBIBI
AT A GLANCE
Bitget CEO said the attack characteristics appear consistent with those of a North Korean hacking group, but attribution and the attack path remain under investigation.
Article
⚡️Bitget CEO suspects North Korean hackers were behind the attack, saying IP clues match VPN characteristics
BlockBeats news: On September 25, Bitget CEO Gracy Chen said during a livestreamed Q&A on the platform security incident that a preliminary investigation found some related IP addresses matched VPN services used by a North Korean hacking group. The attack pattern also resembled the group’s previous actions, so the group’s involvement in the attack, which involved approximately 351.6 million USD, cannot be ruled out. However, the relevant attribution remains at the preliminary investigation stage.
Gracy Chen said Bitget currently does not believe the incident was carried out by insiders. The attackers directly breached the platform’s systems and transferred funds; they did not forge users’ withdrawal requests, nor did they obtain the private keys to cold wallets or hot wallets. Investigators are still determining the specific affected systems and how the attackers gained access.
Original link https://m.theblockbeats.info/flash/368915
Key points
01
BlockBeats said the news was published on September 25.
02
Bitget CEO Gracy Chen said during a livestreamed Q&A on the platform security incident that a preliminary investigation found some related IP addresses matched VPN services used by a North Korean hacking group.
03
Gracy Chen said the attack pattern resembled the previous actions of North Korean hackers, so the group’s involvement in the attack, which involved approximately 351.6 million USD, cannot be ruled out.
04
The original text explicitly states that the relevant attribution remains at the preliminary investigation stage.
05
Gracy Chen said Bitget currently does not believe the incident was carried out by insiders.
06
Gracy Chen said the attackers directly breached the platform’s systems and transferred funds; they did not forge users’ withdrawal requests, nor did they obtain the private keys to cold wallets or hot wallets.
07
Investigators are still determining the specific affected systems and how the attackers gained access.
AI-assisted interpretation
The following is analysis, separate from reported facts. Verify important claims independently.
Bitget’s leadership believes that some network addresses, VPN service characteristics, and attack methods resemble those of a North Korean hacking group, but this is only a preliminary assessment. The platform’s current position is that the attackers breached its systems and then transferred funds, rather than forging users’ withdrawal requests or obtaining the private keys to cold or hot wallets. It is still unclear which system was breached and how.
Why it matters to readers
The incident involved approximately 351.6 million USD, and the affected systems and attack path have not yet been determined. The investigation’s findings will affect how the public assesses Bitget’s system security, fund handling, and subsequent risks.
If you use Bitget, monitor the platform’s subsequent disclosures about the affected scope, service status, and fund-handling arrangements. At this stage, do not treat “suspected North Korean hacking group” as a confirmed conclusion.
Risks and unknowns
Whether a North Korean hacking group was involved has not been confirmed; the current attribution is based only on a preliminary investigation and similarities in characteristics.
The specific affected systems have not been confirmed.
The attackers’ method of gaining access has not been confirmed.
The original text does not state whether the approximately 351.6 million USD constitutes the final loss in full.
The original text provides no arrangements for fund recovery, compensation, or service restoration.
Related Developments
Loading event timeline…
The original text provides no investigation conclusions from independent security organizations or law-enforcement agencies.
Related concepts
IP address
This term is not in the glossary yet. Browse related concepts in the glossary.