Bitget CEO Gracy Chen stated that, according to a preliminary investigation, North Korean hackers may have been behind the $351.6 million exchange hack on Thursday. Investigators identified IP addresses matching VPN usage associated with a North Korean group. The exchange does not consider the incident to be an insider attack.

Preliminary IP Matches and Similarities to Previous Attacks

During a live Q&A session on X, Chen noted that investigators found similarities with previous attacks attributed to North Korea: “We identified several IP addresses that match the VPN choices of a specific North Korean group.” According to her, “the pattern is very similar to what this team has done before.”

Hack Without Withdrawal Manipulation or Wallet Keys

According to Chen, the attackers gained access to Bitget’s systems and transferred funds directly, without falsifying user withdrawal requests. She emphasized that the hackers did not obtain private keys to the cold wallet or any hot or “warm” wallets. The investigation is ongoing as specialists work to determine which systems were compromised and how access was obtained.

Withdrawals Paused, Some Funds Recovered

Earlier, Bitget reported unauthorized transfers affecting part of the hot and “warm” wallet infrastructure. At the time of the statement, withdrawals remained paused. Chen added that some of the stolen funds have already been recovered, without disclosing the amount; the exchange is working with blockchain funds and partners for further recovery.

Context: In 2025, North Korean hackers were linked to crypto asset thefts totaling $2.02 billion, including the Bybit exchange hack of around $1.5 billion, which the FBI attributed to North Korea.