ThreatPaper
Assessed, Not Confirmed

North Korean hackers stole the funds from Bitget

Assessment

Headlines and Bitget itself frame the theft as a suspected North Korean operation. The only attribution on record is CEO Gracy Chen's statement that the intrusion is 'highly consistent with known patterns of North Korean hacker organizations,' based on IP behaviour and on-chain analysis. That is an assessment by the victim, not a forensic or government finding: no national authority or independent body had publicly confirmed a DPRK link at the time of writing, and the supporting datapoint most often cited — TRM Labs' estimate that North Korea is behind roughly three-quarters of 2026 crypto theft — describes the year's landscape, not this specific case. The DPRK direction is a reasonable working hypothesis given that dominance, but presenting it as confirmed overstates single-source, victim-supplied evidence.

Where this claim appeared

TechCrunch · 2026-09-25

https://techcrunch.com/2026/09/25/north-korean-hackers-suspected-in-351m-crypto-theft-the-largest-so-far-this-year/

What “Assessed, Not Confirmed” means

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

4 of 5 · rating scale

Assessed in

Bitget: a backend compromise, not a stolen key, drains ~$387.5M via spoofed transfers

Think this assessment is wrong? Report an error.