As reported by BleepingComputer, Bitget has resumed Bitcoin withdrawals following a $387.5 million theft attributed to North Korean state-sponsored actors. The exchange's CEO, Gracy Chen, confirmed that attackers breached a critical backend system within Bitget's wallet infrastructure and used it to spoof transaction data, tricking the authorization layer into approving transfers from compromised hot and warm wallets across at least seven blockchains.

Threat Intelligence: The exchange's CEO, Gracy Chen, confirmed that attackers breached a critical backend system within Bitget's wallet infrastructure and used it to spoof transaction data, tricking the authorization layer into approving transfers from compromised hot and warm wallets across at least seven blockchains.

The most significant detail here is not the dollar amount—though $387.5 million makes this one of the largest crypto thefts on record—but the attack vector. This was not a smart contract exploit, a private key leak, or a DeFi protocol failure. It was a direct compromise of the trusted backend that governs transaction authorization. By manipulating the data flowing into Bitget's approval workflow, the attackers weaponized the platform's own infrastructure against it.

Why This Attack Pattern Matters

Crypto exchanges have spent years hardening smart contracts, implementing multi-signature wallets, and auditing on-chain logic. But the attack surface that DPRK actors keep exploiting sits off-chain: the internal systems that decide whether a transfer is legitimate before broadcasting it.

The authorization backend is the soft underbelly of every centralized exchange. If an attacker can spoof the data feeding into it, no amount of on-chain cryptography will help.

This is structurally similar to the Bybit heist earlier this year, where attackers manipulated the signing interface itself. The pattern is now clear: DPRK operators are systematically mapping and compromising the off-chain transaction signing and approval pipelines that gate hot and warm wallet withdrawals.

Who Is at Risk

Why This Attack Pattern Matters
Centralized exchanges with hot/warm wallet architectures where a single backend system authorizes transfers
Custody providers using automated approval logic fed by internal APIs
Any platform where transaction signing is triggered by backend state that could be tampered with post-compromise

Smaller exchanges may be in even greater danger—they lack the monitoring maturity of tier-one platforms but share the same architectural exposure.

Broader Implications

Elliptic estimates DPRK has stolen over $6 billion in crypto since 2017. With Bybit ($1.5B) and now Bitget ($387.5M) in a single year, the tempo is accelerating. These are not opportunistic crimes—they are sustained, state-directed revenue operations funding weapons proliferation under heavy sanctions. The 5% recovery bounty Bitget launched is a standard industry response, but historically these programs recover only a small fraction of stolen funds.

The gradual withdrawal resumption schedule—Bitcoin first, then ETH, then USDT, then other assets—reflects the operational reality: each blockchain integration must be independently audited and re-secured before being re-enabled. This is the correct approach, but it also teleports the incident's impact into a multi-week disruption for users.

Shield53 Recommendations

For Crypto Exchanges and Custody Platforms

  • Decouple authorization from backend integrity: Implement independent verification of transaction data using out-of-band attestation. The signing system should cross-check withdrawal requests against a separate, hardened data source—not trust the same backend that may be compromised.
  • Hardware-backed signing enclaves: Move transaction signing into HSMs or TEEs that validate transaction integrity independently of the calling system. The signer must refuse transactions whose metadata doesn't match independently-derived expectations.
  • Rate-limiting and anomaly detection on authorization pipelines: Detect spoofing attempts by monitoring for transaction patterns that deviate from expected withdrawal behavior—unusual amounts, timing, destination clusters, or volume spikes.
  • Network segmentation: The backend system handling withdrawal authorization must not be reachable from general corporate infrastructure. Limit lateral movement paths that could lead to its compromise.
  • Out-of-band confirmation for high-value transfers: For withdrawals exceeding a threshold, require manual confirmation through a separate, air-gapped or heavily isolated approval workflow.

For Users and Institutions

  • Treat exchange hot wallets as inherently risky for large balances. Move long-term holdings to self-custody or qualified custodians with insurance.
  • Monitor on-chain movements of exchange wallets you rely on. Sudden large outflows from known exchange addresses may indicate an incident in progress.
  • Diversify across multiple platforms to reduce exposure to any single exchange failure.

The industry has focused heavily on securing what happens on-chain. DPRK operators are showing that the most lucrative targets remain off-chain. Until exchanges treat their authorization backends with the same rigor as their smart contracts, this pattern will repeat.