#BitgetBreachForgedRequestsNotStolenKeys EXCLUSIVE: THE BITGET $351.6M HACK MAY HAVE LEFT A BIGGER CLUE
Everyone is talking about the possible North Korea connection.
But the more interesting clue may be hiding on-chain. ๐
๐ What investigators are seeing:
โข Bitget says ~$351.6M was affected across its wallet infrastructure
โข The attacker reportedly compromised a backend wallet system, spoofed transaction data and triggered the normal authorization process
โข Private keys were NOT compromised, according to Bitget
โข Around 102.97M XRP โ roughly $157M โ was among the largest stolen portions
โข On-chain analyst Specter says the stolen XRP can be traced to funds connected to the $24M AFX exploit from July
โข That AFX incident has been associated with the TraderTraitor/Lazarus ecosystem
And thereโs another clue:
Bitget CEO Gracy Chen says some attacker IP/VPN patterns resemble infrastructure previously associated with a North Korea-linked group.
โ ๏ธ But this is NOT final attribution yet.
The real question now is:
Did the same North Korea-linked operation move from the AFX exploit to Bitget?
If the XRP trail + infrastructure evidence is independently confirmed, this could turn the Bitget incident from a massive exchange hack into another major Lazarus-linked operation.
๐ฐ Bitget says its $464M+ User Protection Fund can cover the affected amount, while withdrawals remain suspended during the security review.
๐ Watch the XRP wallets.
The blockchain may reveal who is behind the attack before the official investigation does.
#Bitget #XRP #CryptoHack #LazarusGroup #NorthKorea #CryptoSecurity #CryptoNews