Bitget CEO Points to North Korea in $351.6M Hack as Onchain Traces Emerge
Gracy Chen cited IP addresses consistent with a DPRK-linked group’s VPN habits, while an independent researcher flagged a possible connection to the AFX exploit.
Illustration · generated, not a photograph
Bitget’s chief executive said the exchange’s $351.6 million security breach may have been carried out by North Korean hackers, citing initial findings that tie the attack to infrastructure choices known to be used by a Democratic People’s Republic of Korea (DPRK) group.
Gracy Chen spoke during a live X session hours after the theft, telling viewers that security teams identified IP addresses matching the VPN preferences of a particular North Korean collective. She added that the pattern closely resembled prior operations by that team.
Chen also dismissed the possibility of an inside job, saying the exchange does not believe any employee was involved in the incident.
The comments follow a Sep. 24 announcement from Bitget that unauthorized transfers had hit parts of its hot and warm wallet systems. Withdrawals remain paused as of publication time, and Chen said investigators are still working to determine which systems were accessed and how the attackers broke in.
Chen stated that the breach occurred through a backend system of the wallet service, which was exploited to forge transfer instructions and trigger the authorization signing process. She stressed that user withdrawal requests were not tampered with and that cold wallet private keys, as well as hot and warm wallet keys, were not obtained by the attackers.
Independent onchain research appears to support the North Korea theory. A researcher using the handle Specter posted on X that they traced a portion of the stolen XRP to an Ethereum address that received 68,808 USDT from a wallet linked to the AFX exploit, a July incident in which $24 million was taken.
AFX, in its postmortem, said it suspected the involvement of TraderTraitor, a group that security experts have linked to North Korea. Specter’s trace suggests the Bitget funds may have flowed through the same infrastructure connected to that earlier attack.
Chen told the audience that some funds have already been recovered, without specifying how much. She said the exchange is coordinating with blockchain foundations and other partners on recovery efforts.
The potential North Korean link comes amid a sharp rise in such attacks. In 2025, hackers with alleged ties to the DPRK were behind an estimated $2.02 billion in crypto theft, including the roughly $1.5 billion Bybit exploit, which the FBI attributed to North Korean actors.
Source reporting
The outlets whose reporting this account was written from.
Written from the reporting and primary documents credited at the foot of this story. Facts are credited to the outlet or document that established them. How Chainpress works

