Cyber attackers originating from North Korea struck the Bitget cryptocurrency exchange on Thursday, stealing approximately $388 million in digital assets—an amount significantly higher than initial estimates, according to leadership.
Gracy Chen, CEO of Bitget, stated on Friday that this elevated total “reflects a more complete accounting of transfers during the incident.” Her initial report had indicated that upwards of $350 million was siphoned off.
Blockchain security organizations initially detected illicit transactions stemming from the Victoria, Seychelles-registered platform’s hot wallets on Thursday, prompting the company to halt all customer withdrawals.
CoinGecko metrics rank Bitget as the sixth-largest cryptocurrency exchange globally, handling a daily trading volume exceeding $1 billion.
“Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations,” Chen posted on X on Friday.
She further noted: “Our goal is to complete a full recovery as soon as possible. We will announce the specific time window immediately upon confirmation.”
An official security bulletin released by the exchange detailed the compromised digital currencies, which primarily consisted of Ethereum, Tron, and the USDT stablecoin, alongside no Bitcoin. However, records from a stolen funds tracker indicate the perpetrator currently holds over $28.8 million in the premier cryptocurrency.
Cryptocurrency-targeting cybercriminals, particularly those originating from North Korea, have demonstrated increased sophistication and speed relative to the previous year. Industry specialists attribute this heightened efficiency partly to the adoption of artificial intelligence technologies.
United States officials have consistently asserted that state-sponsored North Korean cyber syndicates, including Lazarus, routinely target and loot cryptocurrency exchanges.
Recent digital asset security has drawn intense scrutiny following a wave of breaches that have unsettled the industry. In July alone, malicious actors exploited a firmware vulnerability within the widely used Coldcard bitcoin hardware wallet, making off with nearly $120 million in user assets.
Furthermore, earlier this month, self-described white-hat hackers drained approximately 4,000 bitcoins—valued at around $320 million at the time—from the federation wallet of Blockstream’s Liquid sidechain. The actors subsequently sent back 85% of the funds while demanding to retain the remainder as a ransom days later.
Frequently Asked Questions
How much was stolen from the Bitget crypto exchange?
Hackers stole close to $388 million in digital assets from Bitget.
Who is suspected of carrying out the Bitget hack?
Bitget CEO Gracy Chen stated that the attack method is highly consistent with known patterns of North Korean hacker organizations.
Which digital assets were stolen in the attack?
The stolen assets mostly included Ethereum, Tron, and the USDT stablecoin, though a stolen funds tracker also shows the attacker holding over $28.8 million in Bitcoin.
What position does Bitget hold among crypto exchanges?
Bitget is the sixth largest crypto exchange, processing over $1 billion in trading volume per day.


