Bitget CEO Ties $350 Million Hack to North Korea After 102.9M XRP Drain
Bitget CEO Gracy Chen says North Korean hackers were very likely behind the $350 million hack, led by 102.9 million XRP. Withdrawals remain suspended.
AI SummaryAI
- Bitget CEO Gracy Chen says North Korea was very likely behind the $350 million September 24 hack.
- Attackers compromised a backend wallet system and spoofed transaction data without obtaining any private keys.
- On-chain analysis shows nine assets stolen, led by 102.9 million XRP worth roughly $157.5 million.
- The bridged stolen XRP was linked to the $24 million July AFX Trade exploit attributed to TraderTraitor.
Bitget CEO Points to North Korea
Bitget CEO Gracy Chen says North Korean hackers were “very likely” behind the roughly $350 million breach of her exchange, an intrusion that struck on September 24 and forced a full suspension of withdrawals. Speaking in a live Q&A broadcast on X, Chen said investigators had identified IP addresses matching the VPN preferences of a specific DPRK-linked group, and that the intrusion pattern closely resembles prior operations attributed to North Korean units. She stopped short of naming the group and said the exchange does not believe the breach was an inside job. The incident now sits at the top of DefiLlama’s 2026 hack rankings, and Chen has promised a complete technical report once forensic teams confirm exactly how the attackers got in — the document that will either harden or weaken the attribution her team is currently signaling.
A Backend Breach, Not a Key Theft
Chen’s account of the attack mechanics, laid out in her official post-mortem, rules out the scenarios users fear most: the attackers never obtained private keys for Bitget’s hot, warm or cold wallets, and they did not forge customer withdrawal requests. Instead, she says, they compromised a critical backend system inside the exchange’s wallet infrastructure, used it to spoof transaction data, and tricked Bitget’s own authorization process into moving funds out. She added that losses are contained and no further unauthorized transfers can occur, though investigators are still mapping which servers were touched and how the defenses failed. Some stolen funds have already been recovered, she said, without specifying the amount, with recovery efforts running alongside blockchain foundations and security partners.
laid out in her official post-mortemhttps://x.com/GracyBitget/status/2103284265563902056
102.9M XRP Led the Stolen Assets
On-chain tracing shows the attackers pulled nine different assets, with XRP (XRP) by far the largest component: roughly 102.9 million tokens, valued at about $157.5 million at the time. The haul also included ETH, AVAX and BNB alongside major stablecoins — USDC, USDT and USDT0 routed on Arbitrum. Bitget’s confirmed loss runs about double the roughly $176 million visible in initial on-chain estimates, a gap that reflects assets moved beyond what first-pass monitoring caught. A separate on-chain analysis has added weight to the North Korea angle: analyst Specter reported that the stolen XRP was bridged and links directly to funds from the AFX Trade exploit, a $24 million July theft attributed to TraderTraitor, a Lazarus-associated unit — the same unit LayerZero tied to the KelpDAO bridge exploit in April.
2026’s Largest Hack by Far
DefiLlama’s tracker now logs about $2.2 billion lost across 281 incidents this year, and the Bitget theft alone represents roughly 16% of it — comfortably ahead of September’s $320 million Liquid Network incident and April’s $295 million Drift breach. The event also makes September the costliest month of 2026, overtaking April’s roughly $648 million in losses. TRM Labs data had already found North Korean groups behind 76% of hack losses through April, and the sector’s benchmark remains the $1.5 billion Bybit theft of February 2025, attributed by the FBI to Lazarus. Bybit CEO Ben Zhou has publicly offered to help Bitget trace and recover the stolen funds, returning Bitget’s own assistance after the Bybit hack. The exchange says its User Protection Fund, launched in 2022 and holding above $464 million — including around 5,500 BTC against a $300 million floor commitment — covers the full loss, per the official notice, placing the incident in a lineage of exchange-scale thefts stretching back to Mt. Gox and Coincheck’s NEM haul. Readers tracking the market in real time can follow live spot and futures prices on Gate.
What the Post-Mortem Must Confirm
Our reading of the evidence so far: the attribution rests on IP-and-VPN indicators plus on-chain fund tracing, not yet on a completed forensic report, so the North Korea label should be treated as a strong lead rather than a confirmed finding. The root cause, per the CEO’s own account, was a compromised backend used to spoof transaction data and hijack internal authorization — no keys ever left custody, which is precisely the key-management and signing layer that venues like Coinbase treat as the critical control surface. The remediation path — contained losses, suspended withdrawals, full coverage from the $464 million fund — protects users for now, but anyone deciding whether to hodl assets on centralized venues should wait for the promised technical report, and weigh it against our best crypto exchanges security checklist before drawing conclusions.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


