BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
DeFi

Bitget CEO Suspects North Korea Behind $352M Hack as XRP Trails Point to Lazarus Group

Bitget CEO Gracy Chen suspects North Korean hackers may be behind the exchange’s $351.6 million security breach, citing preliminary links between IP addresses identified during the investigat

AnonymousCryptoCompass newsroom
September 25, 2026
5 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for defi coverage.

Bitget CEO Gracy Chen suspects North Korean hackers may be behind the exchange’s $351.6 million security breach, citing preliminary links between IP addresses identified during the investigation and VPN services previously used by a DPRK hacking group.

Chen said the attack pattern “looks very much like” previous North Korean operations, while Bitget does not believe the breach was an insider job. The attribution remains preliminary. 

Gracy Chen live broadcast. Source: Bitget

The live broadcast follows Bitget’s confirmation on September 24 that attackers compromised a core backend system in its wallet infrastructure, allowing them to forge withdrawal requests and manipulate the automated signing process. The exchange said private keys were not compromised. Blockchain data showed funds were drained across multiple EVM chains, with more than 44% of the stolen assets reportedly in ETH and most funds converted into roughly 67,982 ETH.

On-chain researcher Specter has separately linked some stolen XRP flows to wallets associated with previous North Korea-linked activity. Bitget has temporarily suspended withdrawals while investigating and hardening its security systems, while deposits and spot and futures trading remain operational. The exchange said it is working with independent third-party cybersecurity experts Mandiant and SlowMist to conduct a full investigation into the breach.

DeFi Planet has also received commentary from Lucien Bourdon, Bitcoin analyst at Trezor: 

“If the early signs pointing to North Korea hold up, this would be another major exchange hit by North Korea after Bybit last year. These are state-backed teams with time and money to spend, and an exchange keeps hundreds of millions of dollars behind one set of systems. Finding one way in pays better than almost anything else they could target.

 

Bitget’s customers are covered because Bitget chose to set up a protection fund. These funds are voluntary, so what happens after a hack depends on which exchange you used. With self-custody, you use an exchange to buy and sell, and keep your savings in a wallet where you hold the keys. You’re responsible for your own backup and security habits. In return, you control your own money, and a hack or a regulatory problem at an exchange doesn’t affect it.

Crypto users warn of exchange risk after Bitget hack

Bitget’s $351.6 million breach has sparked a wave of concern among crypto users over keeping large balances on centralized exchanges. On Reddit, some users described the incident as another reminder of self-custody risks, while others questioned whether blockchain tracing can help recover stolen assets. One commenter said they had roughly $12,000 on Bitget when withdrawals were suspended, adding to concerns among affected users.

Other reactions focused on whether Bitget’s protection fund can reassure users after the breach. Crypto commentator crypto_bitlord7 highlighted the exchange’s reported $464 million User Protection Fund and called for efforts to recover the stolen funds. The discussion reflects a broader question among users: whether exchange insurance or protection funds can provide the same confidence as keeping assets in self-custody.

The incident has also prompted warnings about increasingly sophisticated attacks. Ledger CTO Charles Guillemet said on X that AI could make vulnerability research and exploitation cheaper, potentially giving attackers more leverage. His comments have fueled debate over whether exchanges need stronger backend security as attackers increasingly target infrastructure rather than directly compromising private keys.

Also Read: Taiko Halts Bridge Operations After $1.7 Million Exploit

Bitget records the largest crypto theft so far, and Bybit is ready to assist with recovery 

Bitget’s $351.6 million breach has surpassed the $320 million Liquid Network exploit in September, becoming the largest crypto theft reported in 2026 so far. Liquid attackers exploited a validator-software flaw to create unbacked L-BTC and withdrew about 4,000 BTC, later returning roughly 85% of the funds.

Earlier in April, the Drift Protocol and KelpDAO attacks drained approximately $285 million and $292 million, respectively. TRM Labs said those two incidents accounted for about $577 million, or 66% of H1 2026 crypto hack losses, and attributed the activity to North Korea-linked actors.

Bybit CEO Ben Zhou said the exchange is ready to help Bitget trace the stolen assets, noting that Bitget previously supported Bybit after its own hack. Zhou said Bybit was updating LazarusBounty.com to help Bitget track the movement of the stolen funds. The offer comes as Bybit continues its own recovery efforts following its $1.5 billion hack, including legal action against North Korea and the Lazarus Group and measures aimed at freezing stolen assets.

 

Enjoyed this? BookmarkDeFi Planet, explore related topics, and follow us onTwitter,LinkedIn,Facebook,Instagram,Threads, and CoinMarketCap Community for seamless access to high-quality industry insights

Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.

The post Bitget CEO Suspects North Korea Behind $352M Hack as XRP Trails Point to Lazarus Group appeared first on DeFi Planet.