Bitget Hack Losses Reach $387M: North Korea Suspected in Massive Crypto Theft
Bitget has lost $387.5 million in a hack where attackers faked internal transfer requests. The exchange's CEO suspects North Korean hackers. Stablecoin issuers froze some funds, but most were swapped into ETH.
Key takeaways
- Bitget lost $387.5 million after attackers faked internal transfer requests.
- CEO Gracy Chen suspects North Korean Lazarus Group hackers.
- Circle and Tether froze only ~$318K; most funds were already swapped into ETH.
- The attack mirrors tactics from the $1.5B Bybit hack.

Bitget, a major cryptocurrency exchange, has confirmed that hackers stole $387.5 million from its hot and warm wallets. The attackers faked internal transfer requests to drain the funds across multiple blockchains. The exchange's CEO, Gracy Chen, suspects North Korean hackers, citing similarities to previous state-sponsored attacks.
How the Hack Happened
The attackers created a new wallet and drained funds in under an hour. They targeted both hot and warm wallets, which are used for active trading and liquidity. The hack was confirmed after independent researchers flagged unusual movements, and Bitget's CEO acknowledged the breach.
Stablecoin Issuers Freeze Only a Fraction of Stolen Funds
Circle and Tether blacklisted a wallet labeled "Bitget Exploiter 8," locking about $318,000 in USDC and USDT — less than 0.1% of the total haul. By the time the freeze was applied, the attacker had already swapped the vast majority of stolen assets into Ethereum (ETH), which cannot be frozen. This mirrors the pattern seen in the $1.5 billion Bybit hack, where most funds were converted to ETH before issuers could act.
Why North Korea Is a Suspect
Chen's suspicion of North Korean involvement is based on the attack's sophistication and operational similarities to previous hacks linked to the Lazarus Group, a state-sponsored hacking collective. North Korea has been increasingly active in targeting crypto exchanges, as seen in recent lawsuits by Bybit and Aave against North Korea and the Lazarus Group over $1.5B hack, freezes assets. The G7 has also warned of North Korean crypto theft and cybercrime threats.
What This Means for Crypto Users
This hack underscores the limitations of stablecoin freezes as a recovery tool when attackers move quickly to ETH. For everyday crypto users, it's a reminder to use exchanges with robust security protocols and to monitor account activity for any unusual movements.
Frequently asked questions
What happened in the Bitget hack?
Hackers stole $387.5 million from Bitget's hot and warm wallets by faking internal transfer requests. The exchange's CEO suspects North Korean hackers.
How did stablecoin issuers respond to the hack?
Circle and Tether froze about $318,000 in USDC and USDT tied to the hack, but the attacker had already swapped most funds into ETH, which cannot be frozen.
Why is North Korea suspected in this hack?
The attack's sophistication and similarities to previous hacks linked to the Lazarus Group suggest North Korean involvement.
What can crypto users do to protect themselves?
Use exchanges with robust security protocols and monitor account activity for any unusual movements.