Bitget, a major cryptocurrency trading platform, has said it suspects actors linked to North Korea are behind a cyberattack that resulted in the theft of $352 million in digital assets. The company made the attribution public as it disclosed the scale of the incident to users and industry watchers.
Cybersecurity researchers and governments have in recent years linked North Korean-affiliated groups with a number of high-value cyberthefts targeting virtual currencies, and Bitget's statement follows that pattern of attribution. Experts caution, however, that attributing cyberattacks to nation-states can be complex and typically relies on technical indicators, historical patterns and intelligence not always available to the public.
The incident underscores continuing vulnerabilities in the cryptocurrency ecosystem, where large, rapid transfers and cross-border anonymity make stolen funds difficult to recover. Exchanges and other service providers regularly face pressure to improve security and to collaborate with law enforcement and blockchain tracing firms to track and freeze illicit proceeds.
Authorities and private security firms often work together in such cases to trace the movement of stolen tokens and to alert other platforms to block suspicious transfers. Bitget’s disclosure is likely to intensify scrutiny of security practices across the industry and may prompt further action by regulators and investigators focused on stopping the laundering of assets tied to state-backed cybercrime.
The broader crypto sector has been under increased regulatory and public scrutiny following a series of thefts and frauds in recent years. Whether investigators will be able to recover any of the $352 million or definitively confirm the involvement of North Korean operatives remains uncertain and may take time as tracing and enforcement efforts proceed.