Sharespulse
sharespulseTelegram

Bitget Points Finger at North Korea After $352 Million Crypto Hack

Crypto Security·October 5, 2026

Bitget, one of the larger crypto trading platforms, has said it suspects North Korea is responsible for a hack that drained about $352 million. The attribution is a suspicion rather than a confirmed finding, and the full technical picture of how the attackers got in has not been laid out in the information available so far.

The size of the theft alone makes it a serious event for the exchange and for the wider market. A loss of this scale tests an exchange's reserves, its relationships with users, and the confidence of traders who park funds on centralized platforms. How Bitget covers the shortfall, and whether customer balances are affected, will be central questions in the coming days.

Pointing at North Korea is not a surprise in the context of crypto crime. Blockchain analytics firms and Western governments have for years tied hacking groups linked to Pyongyang to some of the biggest thefts in the industry. Investigators say those groups tend to favor exchanges and bridges, then move stolen funds through a chain of wallets and mixing services before cashing out. Authorities have alleged that the proceeds help fund the country's weapons programs, a claim North Korea has consistently rejected.

For investors, the immediate concern is less about price action and more about counterparty risk. Every large exchange hack revives the old argument over self-custody versus leaving assets on a platform, and over how much transparency exchanges owe users about proof of reserves and security practices. Exchanges that suffer breaches usually face a period of scrutiny from regulators, partners and customers, even when they promise to make users whole.

What to watch next is straightforward. First, whether Bitget publishes a detailed account of the breach and confirms the attribution with evidence. Second, whether on-chain investigators trace the stolen funds and whether any can be frozen as they move toward exchanges or other off-ramps. Third, how the platform handles withdrawals and user compensation while the investigation continues.

Until those answers arrive, the suspicion of North Korean involvement should be treated as a working theory. Even so, it fits a pattern that the crypto industry has been struggling to defend against for years: well-resourced, persistent attackers going after the places where the largest pools of digital assets sit.

Reporting based on an external source.