Bitget CEO suspects DPRK group behind $351.6M hack, citing VPN IP clues

By Crypto Wire
September 24, 2026

Bitget CEO Gracy Chen said in a live X Q&A after the exchange’s $351.6 million hot-and-warm wallet breach that preliminary investigators flagged IP addresses matching VPN choices linked to a DPRK hacking group, according to Cointelegraph’s September 25 wrap. Chen said the pattern “looks very much like what the North Korean team did before,” and that Bitget does not believe the incident was an inside job. That is the unused Rug Room follow-up to LN 9688, which logged the confirmation, withdrawal pause, and $464 million-plus User Protection Fund claim—without any DPRK or Lazarus attribution. Attribute the North Korea link as Chen’s preliminary company claim, not as an FBI indictment or closed forensic report.

What Chen added about how the money moved. Cointelegraph quotes her saying attackers breached Bitget systems and transferred funds directly rather than forging customer withdrawal requests, and that they did not obtain private keys for cold, hot, or warm wallets. Investigators are still determining which systems were compromised and how access was gained. A separate ChainCatcher wrap of the same broadcast says Bitget is preparing to resume withdrawals but has no accurate reopen timeline yet, and that the attack path differs from classic key-leak exchange thefts. Chen also said the platform has completed broader loss-prevention steps and does not expect a repeat drain while withdrawals stay gated across multiple chains and assets. Desk rule: keep the “no private-key leak,” “system bypass,” and “no reopen clock” language as CEO statements pending Bitget’s promised full incident report.

How this differs from the first Bitget post. LN 9688 carried the 18:31 UTC detection, the company $351.6 million estimate, the hot/warm vs cold split, the withdrawal freeze, and the protection-fund coverage claim above $464 million. It did not include a nation-state attribution. Tonight’s tape is the Q&A: VPN/IP clues pointing at a DPRK group, a denied insider narrative, a denied forged-withdrawal path, an explicit no-keys-obtained claim, and a soft recovery update without a published reclaim total. Readers who already saw the first post still get a new operational fact set; readers who missed it get enough context to understand why the pause continues without reprinting the full on-chain hop map from Decrypt’s early $183 million cluster.

Recovery color without inventing a dollar figure. Chen said some stolen funds had been recovered without specifying an amount, and that Bitget is working with blockchain foundations and other partners on recovery, per Cointelegraph. Hackread’s September 25 write-up frames Bitget’s belief that Lazarus Group may be involved, while noting that no technical evidence supporting that named attribution had been published at press time. Prefer Cointelegraph’s tighter “DPRK group / VPN IP match” quote for the lead fact; treat named “Lazarus” branding as secondary attribution that still awaits public IoCs. North Korean operators were linked to an estimated $2.02 billion in crypto theft in 2025, including the roughly $1.5 billion Bybit hack the FBI attributed to North Korea—backdrop only, not proof Bitget’s path matches Bybit’s signing-screen playbook.

Why NFT and settlement readers still care on night two. Centralized venues remain where collectors buy ETH, SOL, and stables before marketplace bids. With withdrawals still suspended and attribution now pointing at a state-linked playbook, the operational message is unchanged from 9688 but sharper: treat Bitget balances as frozen inventory until an official reopen, keep fresh NFT settlement floats in self-custody, and watch whether recovered chunks and foundation partner freezes change the on-chain trail. Deposit and trading rails may still look “live” on the front end while exits are gated—do not confuse deposit availability with settlement liquidity. Leave Payy, Meter Passport, and Duelbits stacks closed—this post is only the DPRK-attribution and attack-path update on Bitget.



What not to invent. Do not invent a recovered-dollar total, a named root-cause CVE, a confirmed Lazarus IOCs dump, an insider-exoneration certificate, or a withdrawal reopen clock. Do not claim cold wallets were drained or that every labeled on-chain Bitget wallet equals customer liability dollar-for-dollar. Stick to Chen’s Q&A quotes as carried by Cointelegraph and ChainCatcher, the still-paused withdrawals, the original $351.6 million company estimate, and the protection-fund coverage claim already on file. Phygital desk 59 stays unused on this OC day—no fresh unused vaulted-card or Luxury Drop result cleared the six-hour window without colliding with Charizard 9640 / Luxury Drop 9646—so this tick stays on Rug Room 52 with Latest News 16.

Bottom line: Bitget’s Chen says preliminary IP/VPN clues point at a DPRK hacking group behind the $351.6 million breach, denies forged user withdrawals and private-key theft, and still has no firm withdrawal reopen timeline while some funds are reportedly in recovery.

Disclaimer: This article is provided for informational and educational purposes only. It does not constitute financial, investment, legal, or trading advice. The NFT market is highly volatile, and past performance is not indicative of future results. Readers should conduct their own research and consult qualified professionals before making any decisions related to digital assets. The cover image for this article may have been created using artificial intelligence (AI).

8bitcrypto NewsDesk

Crypto Wire — she runs the default news desk from Los Angeles. Market tape, NFT drops, and policy wires filed fast with zero shill. Your straight signal from 8bitcrypto.

Leave a Reply

Discover more from 8bitcrypto

Subscribe now to keep reading and get access to the full archive.

Continue reading