A massive $352 million hack has struck the crypto ecosystem, and all eyes are now turning to Pyongyang. The CEO of Bitget has spoken out to confirm that losses are contained — but also to name a high-profile suspect: the Lazarus Group, North Korea’s state-sponsored cyber warfare unit.
Behind this staggering figure lies an operation of rare sophistication, bearing all the hallmarks of a state-level actor with extensive experience exploiting crypto infrastructure at scale. Here is what we know so far.
$352 Million Stolen: What We Know About the Attack
The hack, whose scale places it among the most significant incidents in recent crypto history, triggered an immediate response from Bitget. The platform’s CEO publicly confirmed that loss containment mechanisms were activated and that the situation is now under control. No precise technical details regarding the attack vector have been officially disclosed, but early on-chain analysis points toward a compromise of private keys or signing infrastructure.
This type of attack — targeting the deepest security layers of an exchange directly — is the operational signature of the Lazarus Group. The stolen funds were rapidly dispersed across multiple addresses, a layering technique well documented in previous reports by Chainalysis and the United Nations on North Korean cybercriminal activity.
At this stage, on-chain investigations conducted by several blockchain security firms are ongoing in an attempt to trace the fund flows and potentially freeze a portion of the assets on partner centralized exchanges.
Lazarus Group: The Prime Suspect Behind Major Crypto Hacks
The Lazarus Group is no stranger to the crypto world. According to data compiled by Chainalysis, this North Korean state-affiliated hacking collective is believed to have stolen more than $3 billion in cryptocurrencies between 2017 and 2023. Among their most notable exploits: the Ronin Network bridge hack ($625M) in 2022 and the attack on Harmony Horizon ($100M).
Their modus operandi is now well established: social engineering targeting developers, exploitation of vulnerabilities in smart contracts or custody infrastructure, followed by laundering through mixers such as Tornado Cash or intermediary chains. The CEO of Bitget stated that Lazarus involvement is “highly likely” — a carefully worded assessment that carries significant weight in the current geopolitical climate.
This attribution, even if unofficial, raises a structural question for the entire industry: faced with state-level actors operating with virtually unlimited resources, are the current security standards of centralized exchanges truly sufficient? US and European regulators may well seize on this incident to accelerate cybersecurity requirements for crypto platforms.
What Are the Consequences for Trust in Centralized Exchanges?
Every hack of this magnitude reignites the fundamental debate between centralized custody and self-custody. While Bitget claims to have contained the losses — suggesting that user funds are not directly impacted thanks to the exchange’s reserves — the sector’s reputation takes yet another hit. Institutional investor confidence, already fragile following the FTX and Celsius collapses, remains a precious and hard-to-rebuild asset.
On the market side, events of this nature typically generate short-term volatility in the affected assets, with mass withdrawals from platforms perceived as vulnerable. A growing number of users are temporarily migrating to cold wallet solutions in the hours following a major breach announcement.
The incident also underscores the urgency for exchanges to strengthen their multi-signature protocols, MPC (Multi-Party Computation) frameworks, and regular third-party security audits — standards that the most serious players in the market are gradually adopting, though far from universally.