Bitget Explains $350 Million Attack: How Were Funds Moved Without Stolen Wallet Keys?
Bitget’s CEO said the private keys to its wallets were not compromised in an attack that cost approximately $350 million; instead, the attackers breached the exchange’s internal system and transferred the funds.
According to a report by Wu Blockchain on September 25, Bitget detected unauthorized transfers from several of its hot wallets on September 24. CEO Chen’s latest statement focuses on how the attackers accessed the funds following the previously announced loss.
Chen said the attackers did not obtain the private keys to the hot, intermediate-layer, or cold wallets. Instead, according to the CEO, the attackers breached the exchange’s internal system and transferred the funds directly. The statement did not provide further details on how this access was technically obtained.
What is behind the suspicion of a North Korean connection?
Chen said that the VPN usage patterns at the IP addresses identified by the team matched patterns associated with a particular North Korea-linked group. Based on these findings, he said he considered a North Korean connection to the attack “very likely.”
This assessment is based on the CEO’s statement; the information shared does not present the attackers’ identities as definitively established. The source also does not name the group in question.
Previous statement on the protection fund
Bitget had previously announced that its user protection fund exceeded $464 million and was sufficient to cover the loss. The approximately $350 million cited in the new statement refers to the same attack; it is not a separate attack added to previous losses.
The exchange had also previously announced that it had [temporarily suspended withdrawals due to a security review](https://koinbulteni.com/bitget-saldiri-sonrasi-para-cekimlerini-durdurdu-kullanicilar-icin-ne-acikladi-287895.html). The latest post does not say that withdrawals have resumed.