Bitget, the Seychelles-based exchange that ranks among the world’s top six by daily volume, disclosed that a cyber-attack resulted in the loss of roughly $388 million in digital assets. The figure exceeds the initial estimate of $350 million presented shortly after the incident.

Attack Overview

Security firms observed irregular activity on Bitget’s hot wallets on Thursday, prompting the platform to halt all withdrawals. The unauthorized transfers targeted a mix of tokens, with Ethereum, Tron and the USDT stablecoin constituting the bulk of the stolen value. No Bitcoin was reported among the missing assets, though a public tracker shows the perpetrators hold about $28.8 million worth of the leading cryptocurrency.

Attribution to North Korean Actors

Bitget’s chief executive, Gracy Chen, linked the method of compromise to patterns previously associated with North Korean state-sponsored groups. She cited both IP-behavior analysis and blockchain forensics as evidence that the operation aligns with tactics used by entities like the Lazarus Group, which U.S. authorities have long accused of targeting crypto platforms.

Assets Stolen and Ongoing Recovery

The exchange said it has identified the specific tokens taken and is pursuing a full recovery. Chen announced that Bitget will disclose the exact time window for the illicit transfers once verification is complete. In the meantime, the platform continues to keep withdrawals disabled while it works with investigators and security partners.

Broader Context of Crypto Security

The Bitget breach adds to a series of high-profile crypto thefts in 2024, underscoring the growing sophistication of threat actors. Recent incidents include a firmware exploit on the Coldcard hardware wallet that netted nearly $120 million and a white-hat-styled raid on Blockstream’s Liquid sidechain that temporarily removed 4,000 BTC. Analysts note that the adoption of artificial-intelligence tools by hackers is accelerating their ability to locate and exploit vulnerabilities.

Why it matters

The loss of nearly $388 million from a major exchange highlights persistent security gaps in the crypto ecosystem, especially around hot-wallet management. Attribution to North Korean groups reinforces geopolitical dimensions of cyber-crime, suggesting that state-backed actors continue to view digital assets as a lucrative revenue source. For users and regulators, the incident serves as a reminder to demand stronger safeguards, transparency, and rapid response mechanisms from crypto service providers.