Bitget CEO Points to North Korea in $352M Exchange Hack
Bitget CEO Gracy Chen says preliminary findings link IP addresses in a $352M hack to VPN patterns tied to a North Korean hacking group.

Adrian Cole
Markets & Mining Editor, RefreshCoin
Bitget is at the center of a $352M hack that its chief executive links to North Korea. CEO Gracy Chen said a preliminary investigation found IP addresses consistent with VPN choices associated with a DPRK hacking group. The disclosure identifies both the scale of the loss and an early theory about who was behind it. The amount makes the case relevant for exchange counterparty risk across centralized trading venues. Attribution is still preliminary, so the IP match is a starting lead rather than a final finding.
What happened at Bitget?
Bitget disclosed a $352M hack that prompted an internal technical review of network traces and system logs. The review focused on connections observed during or around the incident window and how they map to known infrastructure. Chen said investigators identified IP addresses that matched VPN choices linked to a DPRK hacking group. The company described those findings as preliminary, which means conclusions can change as analysts verify more data.
The $352M figure defines the scale of funds involved and frames the operational impact. For a centralized exchange, a loss of that size raises questions about hot wallet exposure, withdrawal controls and transaction monitoring. It also sets the scope for damage assessment, recovery work and balance sheet pressure. Traders use the headline number as a first gauge of severity before address level proof appears.
Why a $352M loss matters now
A nine figure exchange loss matters because liquidity and trust can react quickly to security failures. A $352M hole can force an exchange to pause withdrawals, rotate keys, move funds to cold storage and review internal access. Those steps can affect order books, funding flows and short term activity even for users not directly affected. Timing is critical because crypto markets reprice counterparty risk within hours of disclosure.
The North Korea claim adds weight because DPRK linked actors have a long record of targeting crypto platforms for large thefts. Past campaigns have touched exchanges, bridges, wallet software and developer supply chains, often followed by layered laundering. That history makes any DPRK link relevant for compliance teams, investigators and peer exchanges. It also explains why attribution claims draw fast attention from security researchers.
The IP and VPN clue explained
IP addresses identify network endpoints, but attackers routinely hide them with commercial VPNs and rented servers. Investigators look for reuse of VPN exit nodes, configuration patterns and address ranges seen in prior intrusions. Chen pointed to a match between addresses in the Bitget case and VPN choices associated with a DPRK hacking group. A match of this type is a useful lead, but it is not proof of identity on its own. Evidence is thin.
VPN clues carry clear limits because addresses can be shared, resold, spoofed or reused by unrelated users. Stronger attribution usually combines malware samples, wallet clustering, timing analysis, domain registrations and infrastructure overlap. Human intelligence and law enforcement data can add further confirmation when available. That is why Chen framed the current finding as preliminary rather than conclusive.
Exchanges typically preserve logs, withdrawal records, session data and device fingerprints after a large hack. External security firms are often brought in to confirm internal findings and rule out false positives from shared infrastructure. Confirmation can take weeks because analysts must exclude other explanations for the same IP overlap. Until that work is complete, the IP link remains one data point among several competing hypotheses.
What does the North Korea link mean for traders?
It means traders should treat counterparty and laundering risk as elevated until Bitget shares harder evidence. DPRK linked thefts have often been followed by complex laundering across chains, exchanges and over the counter desks. Compliance teams may flag deposits connected to the hack, which can delay withdrawals or freeze specific funds. In the short term, that raises operational risk more than directional price risk.
The link does not by itself explain how customer balances are affected or which systems were breached. It does not confirm which wallets were drained, whether cold storage was touched, or how access was first gained. Those facts would normally come from a full post mortem with addresses, timelines and transaction records. Without that detail, traders are left pricing uncertainty around the venue.
How do exchange hacks affect markets?
Large exchange hacks can pressure prices when stolen coins are moved and sold into thin order books. They can also widen spreads when market makers reduce exposure to the affected venue and cut quotes. Broader contagion is less common unless the loss threatens solvency or triggers mass withdrawals across platforms. A $352M event is large enough to justify close watch for venue specific stress and cross exchange spillover.
The market also watches for onchain fund movements after a major hack is disclosed. Transfers from attacker controlled wallets can create headline risk for tokens with lower liquidity and concentrated holdings. Exchanges often coordinate to block listed addresses, which limits cash out routes and pushes attackers toward longer laundering chains. That coordination is one reason early attribution claims get amplified by traders and compliance desks.
What should traders watch next?
Traders should watch for wallet addresses, audit statements and a confirmed timeline from Bitget. The usual next step is a technical post mortem that lists what was taken, when it moved and how access was gained. Investigators may also publish indicators such as IPs, domains and wallet clusters for peer screening. Those details let other exchanges filter deposits and help analysts test the DPRK claim with independent data.
Regulatory and law enforcement responses are another catalyst to monitor in the coming weeks. Large hacks often draw attention from cybercrime units, financial intelligence teams and sanctions authorities. Any asset freeze, advisory or formal attribution would carry more legal weight than a company statement. Continued silence on reimbursement, audits and remediation would extend uncertainty for users of the platform.
Risk now centers on customer impact, security gaps and further outflows from the exchange. If withdrawals remain orderly and balances are accounted for, confidence can stabilize while the investigation continues. If attack vectors remain unknown, the risk of repeat access stays relevant for risk managers. Clear dates for reports, security upgrades and independent reviews will matter more than speculation about motives.
Frequently asked questions
Did Bitget prove North Korea was behind the hack?
No. CEO Gracy Chen described the link as preliminary and based on IP addresses matching VPN choices tied to a DPRK group. Full attribution would need malware, wallet and infrastructure evidence plus independent confirmation.
What does the VPN IP clue actually show?
It shows network overlap, not identity. Attackers use VPNs to hide origin, so investigators compare exit nodes and usage patterns with past cases. Shared infrastructure means the clue must be checked against other data.
How large is a $352M exchange hack?
It is a nine figure loss and large by exchange incident standards. Losses at that scale can affect liquidity, operations and user confidence. The figure alone does not show how customer funds are impacted.
Comments(0)
No comments yet. Be the first to weigh in.