North Korean hackers are suspected of stealing $387.5 million (€332.8 million) in cryptocurrency from Bitget, one of the world's largest exchanges, in what appears to be the biggest crypto theft of the year. The attack, detected on Thursday, targeted the exchange's hot and warm wallets—systems that are connected to the internet for faster transactions—while its more isolated cold wallets remained untouched.
Bitget CEO Gracy Chen said in a livestream that the company identified IP addresses whose VPN usage matched that of a known North Korean group, making a North Korean connection "very likely." In a post on X, she added: "We've identified IP addresses that match the VPN choices by a certain [Democratic People's Republic of Korea] DPRK group. We think this is very likely to be attacked by North Korea."
The attackers did not obtain the private keys to Bitget's wallets, Chen noted. Instead, they breached an internal system and inserted false transaction information, tricking the exchange's approval system into processing fraudulent transfers as legitimate.
Impact and response
Bitget assured customers that its user protection fund, which held over $464 million (€398.5 million) at the time, is sufficient to cover the loss. Customer account balances remain accurate, and deposits and trading have continued. However, withdrawals were temporarily suspended as a precaution, with a phased restoration planned from 28 September.
The company has notified law enforcement and is working with security firms to trace the stolen funds. Chen also revealed that individuals she identified as members of Lazarus, a North Korean state-linked hacking group, had previously approached her posing as a journalist to arrange a Zoom interview.
According to blockchain intelligence firm TRM Labs, this is the largest cryptocurrency theft reported so far this year. The incident underscores the growing threat of state-sponsored cybercrime, which has become a significant source of revenue for the isolated regime.
North Korea has long been accused of using stolen virtual assets to fund its nuclear weapons and ballistic missile programmes, a charge echoed by the US Treasury Department. TRM Labs reported that North Korean groups accounted for 76% of the value stolen in cryptocurrency hacks through April 2025, before the Bitget incident.
In February 2025, North Korean hackers stole approximately $1.5 billion (€1.28 billion) from exchange Bybit, according to the FBI. The agency said the hackers quickly converted some assets into other cryptocurrencies and distributed them across thousands of addresses to obscure their trail.
While North Korea has developed sophisticated cyber capabilities, its government severely restricts ordinary citizens' access to the global internet. The country's cyber operations are believed to be directed by elite units like Lazarus, which have been linked to numerous high-profile attacks worldwide.
For Europe, the incident raises concerns about the security of digital assets and the potential for such thefts to finance destabilising activities. The continent has been increasingly focused on regulating cryptocurrency markets, with the EU's Markets in Crypto-Assets (MiCA) framework set to introduce stricter oversight. As cyber threats evolve, European regulators and exchanges will need to bolster their defences against state-sponsored hackers.


