Spoofed Data and North Korean Links
Bitget revealed a massive security breach on September 24, resulting in the theft of $387.5 million. The incident occurred when attackers manipulated internal systems to drain funds from both hot and warm wallets. This significant loss marks one of the largest crypto exchange hacks in recent history.
Breaking news
Spiral Integrates Bitcoin Payments into Mesh LLM for Machine-to-Machine AI Compute Trading
Strike Introduces Stacks to Organize Bitcoin Savings Into Custom Buckets
CFTC Chair Announces New Crypto Rulemaking to Prevent FTX-Style Collapse
Binance Expands Margin Collateral Options with New Equity-Linked TokensThe attack did not involve the direct theft of private keys. Instead, cybercriminals spoofed transaction data to create the appearance of legitimate internal transfers. This deception tricked the exchange’s approval mechanisms into releasing assets without proper verification. The method highlights a critical vulnerability in how automated systems handle internal fund movements.
The stolen portfolio included approximately 103 million XRP, valued at $157 million at the time of the breach. The remaining funds comprised other digital assets held in the exchange's operational wallets. Bitget CEO Gracy Chen stated that the technical execution of the attack bears strong similarities to previous incidents. Specifically, the IP addresses used and the on-chain patterns align with methods attributed to North Korean state-sponsored hackers.
Why Did Internal Controls Fail
Chen emphasized that the group behind the hack likely utilized sophisticated social engineering techniques alongside technical spoofing. The attackers convinced the system that the transfers were authorized internal operations. This approach bypassed standard security checks designed for external transactions. The precision of the attack suggests a highly organized and well-resourced threat actor.
The failure of internal controls raises serious questions about the robustness of current exchange security protocols. While hot wallets are known to be more vulnerable, the compromise of warm wallets indicates a deeper systemic issue. Warm wallets typically hold larger reserves and are considered more secure than hot wallets due to reduced internet exposure. The ability to drain both types suggests the attackers had significant insight into the exchange's internal architecture.
Security experts note that relying solely on automated approval for high-value internal transfers poses a substantial risk. The spoofed data likely mimicked the exact format and metadata of genuine internal requests. This made the fraudulent transfers nearly indistinguishable from legitimate business operations. The incident underscores the urgent need for multi-layered verification processes for all significant fund movements.
The aftermath of this breach will likely trigger a broader industry review of internal security practices. Regulators may scrutinize exchanges more closely to ensure they implement adequate safeguards against such sophisticated spoofing attacks. Users of Bitget may face temporary service disruptions as the platform works to secure its remaining assets and investigate the full scope of the intrusion. The crypto market may experience volatility as investors reassess the safety of their holdings on centralized exchanges.
Frequently Asked Questions
How much money was stolen from Bitget? The total loss from the breach is estimated at $387.5 million. This includes roughly 103 million XRP, which was valued at $157 million during the attack.
Who is suspected of carrying out the hack? North Korean state-sponsored hackers are the primary suspects. Investigators noted that the IP addresses and on-chain activity patterns match techniques previously used by this group.
Did the attackers steal private keys? No, the attackers did not steal private keys. They spoofed transaction data to trigger legitimate-looking transfer approvals from the exchange's internal systems.

