Crypto exchange Bitget said it detected unauthorized asset transfers on Thursday, with losses totaling about $357 million. Blockchain analytics firm Elliptic said in a report that the laundering route used after the attack, along with the on-chain data, points to TraderTraitor, a hacking group linked to North Korea.
Bitget confirms unauthorized outflows from its wallet
Bitget said its wallet saw unauthorized fund transfers involving multiple tokens, with losses estimated at roughly $357 million. The exchange suspended withdrawals after the incident and said its offline cold wallets were not affected.
CEO Gracy Chen later said Bitget’s $464 million user protection fund is sufficient to fully cover the $357 million loss and protect users. She also said the platform was working at full speed to prepare for the resumption of withdrawals, with an update scheduled for 4:00 UTC on Sept. 26, which corresponds to 12:00 p.m. Taiwan time.
Elliptic says laundering pattern matches TraderTraitor
According to Elliptic, the attackers quickly swapped tokens after the theft and moved the assets across chains. The firm said the laundering methods and overlaps in wallet addresses closely match the traits of TraderTraitor, a North Korea-linked hacking group it has been tracking.
The report added that some of the funds were connected to addresses used in previous attacks, including last year’s record $1.5 billion theft from crypto exchange Bybit.
North Korea-linked groups have stolen about $1.2 billion this year, Elliptic says
Elliptic said North Korea-linked hacking groups have been involved in more than 50 digital-asset security incidents this year, with about $1.2 billion stolen in total. The Bitget incident brings the amount stolen by such groups this year to roughly that level.
The firm also said that over the past decade, North Korea, under international sanctions, has continued to treat crypto institutions as an important funding channel, moving billions of dollars in digital assets since 2017. Its analysis said hackers have also started using newer technologies such as artificial intelligence, increasing the complexity of cross-chain attacks and exploit activity.
Bitget brings in outside security firms
Bitget said it is working with security firms Mandiant and SlowMist to trace the source of the attack and examine the details of the vulnerability. The exchange said it is continuing its investigation and recovery work after suspending withdrawals.
As of publication, Bitget planned to release more information on withdrawal resumption at 4:00 UTC on Sept. 26.

