A $387.5 Million Breach That Exploited Trusted Infrastructure
TREE NEWS reports: Bitget has disclosed that hackers manipulated the exchange’s internal approval system to siphon $387.5 million in digital assets. The attack did not rely on brute-force cracking of private keys; instead, it turned the platform’s own transaction-signing logic into a weapon. The timeline released by Bitget shows a carefully orchestrated sequence that began weeks before the actual theft, with attackers probing withdrawal and approval workflows.
Timeline of the Attack
The first signs of compromise appeared when anomalous API requests were logged from a set of IP addresses later linked to known North Korean threat actors. The attackers allegedly gained access to a privileged internal tool used to approve large transfers. Once inside, they bypassed multi-signature checks by exploiting a misconfigured approval module that treated certain administrator actions as pre-authorized. Within minutes, funds were moved to a series of mixers and cross-chain bridges.
North Korean Links and Industry Implications
On-chain analysts have traced the stolen assets through wallets associated with Lazarus Group, the state-sponsored hacking collective blamed for billions in crypto thefts. The Bitget incident underscores a growing trend: centralized exchanges are no longer breached through smart contract bugs but through the very systems designed to protect them. The attack vector—abusing internal approval mechanisms—echoes earlier incidents at other major platforms, suggesting a systematic targeting of operational security gaps.
For the broader DeFi and CeFi ecosystems, the implications are stark. Exchanges must now treat internal approval tools with the same rigor as public-facing smart contracts. Real-time monitoring, zero-trust architecture, and mandatory multi-party computation for large transfers are no longer optional. Regulators are likely to cite this case as evidence for stricter custody and reporting rules.
Forward-Looking Perspective
Bitget has pledged to reimburse affected users and is cooperating with law enforcement. However, the reputational damage and the precedent set by a $387.5 million internal approval failure will linger. As North Korean actors refine their tactics, the industry must shift from reactive audits to proactive, AI-driven anomaly detection. The next wave of exchange security will not be about preventing hacks—it will be about ensuring that even a compromised insider cannot approve a theft.




