North Korean Hackers Steal $387.5 M from Bitget Exchange, Prompting Withdrawal Pause
What Happened — Bitget, a major cryptocurrency exchange, confirmed that attackers breached its wallet‑backend infrastructure, spoofed transaction data, and moved roughly $387.5 million from hot and warm wallets. The exchange halted all Bitcoin withdrawals, later resuming them after patching the exploited vulnerability and reinforcing its transaction‑authorization controls.
Why It Matters for Trust & Control Assurance
- The incident illustrates a failure of transaction‑authorization and access‑control safeguards that continuous‑control programs are designed to monitor, test, and evidence.
- Demonstrates the need for defensible audit trails of privileged actions on wallet‑management systems, a core control objective across NIST CSF 2.0 and other frameworks.
- Highlights how real‑time detection and rapid remediation of backend flaws are essential to maintain a trustworthy financial‑service posture.
Who Is Affected – Cryptocurrency exchanges and other digital‑asset platforms that manage hot/warm wallets; their customers’ funds and market confidence.
Recommended Actions –
- Conduct an immediate review of wallet‑admin access rights and enforce least‑privilege principles.
- Implement multi‑factor authentication and cryptographic signing for all transaction‑initiation processes.
- Deploy continuous monitoring of privileged actions and maintain immutable logs for audit readiness.
- Validate that incident‑response playbooks cover transaction‑spoofing scenarios and test them regularly.
Source: BleepingComputer
Technical Notes – Attackers exploited a backend vulnerability that allowed them to spoof transaction data, bypassing the exchange’s authorization checks. The breach affected Bitcoin, Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, Base, and related tokens. No personal data was reported as compromised; the loss was purely financial.