Bitget reports $351.6M crypto theft tied to North Korea-linked hackers
Moyen · Security Affairs ·
En bref
- Bitget detected unauthorized transfers from hot and warm wallets on Sept 24.
- Roughly $351.6 million in customer assets was taken.
- Withdrawals were temporarily suspended while Mandiant investigated.
- Hackers tied to North Korea are suspected in the attribution.
- No CVE was involved; this was an operational compromise.
Bitget disclosed on September 24 that attackers moved assets out of its hot and warm storage without authorization. The exchange put a temporary hold on customer withdrawals as it began investigating. The estimated loss is $351.6 million, making it one of the larger exchange incidents this year.
Attribution points to intruders associated with North Korea, according to analysis from Mandiant. The incident did not involve a software vulnerability tracked as a CVE; instead, it appears to be an operational security failure or credential compromise. Bitget has engaged Mandiant to conduct forensic work.
Customers with funds on Bitget are directly affected, especially those unable to withdraw during the pause. The suspension can amplify panic and liquidity pressure even if most assets remain safe. For K-12 and government IT teams, the event is a reminder that third-party financial and crypto services carry supply-chain risk.
Crypto exchanges remain high-value targets because transactions are irreversible and hot or warm wallets must stay online for operations. North Korea-linked groups have repeatedly targeted such platforms to fund state programs. The $351.6 million figure may be revised as tracing continues.
What to watch: when Bitget restores withdrawals, whether it publishes a reimbursement plan, and what Mandiant's final report says about initial access. Also monitor for related phishing or social engineering against exchange users. No CVE means patching alone would not have stopped this; access controls, monitoring, and key management matter.
À faire maintenant
- Immediately rotate credentials and API keys for any service that touches exchange or treasury accounts, and enforce phishing-resistant MFA.
- Review third-party crypto and financial vendors, require incident notification clauses, and pause new integrations until Bitget's forensic report is available.
- Monitor dark web and credential-stuffing feeds for district staff accounts that reuse passwords on exchange or wallet services.
- Restrict hot and warm wallet signing authority to least privilege and require multi-person approval for outbound transfers.
- Run a tabletop exercise for third-party financial service outage or theft, including communication to staff, parents, and finance teams.
- Enable alerting for unusual outbound transfers and login anomalies from exchange or payment platforms.
Source originale
Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.