A September 25 source reports that Bitget has blamed North Korea for a $387.5 million cryptocurrency wallet raid. The exchange’s claim appears in a single-line summary with no accompanying on-chain data, wallet addresses, transaction hashes, or timeline for the alleged theft.
The claim and its provenance
The attribution comes from a published digest dated three days ago. Bitget is named as the accuser; North Korea is named as the culprit; the figure is given as $387.5 million. No regulator, law-enforcement agency, or blockchain analytics firm is cited in the summary as corroborating the assessment. The venue of the alleged breach, whether a hot wallet, a bridge contract, or a custodial arrangement, is not specified.
What is not in the public record
The source contains no technical breakdown. There is no mention of Lazarus Group infrastructure, no IP overlaps, no laundering path through mixers or DEXs, and no reference to a UN Panel of Experts report linking the activity to Pyongyang. The dollar amount is precise to the half-million, yet the method of valuation, mark-to-market at time of theft, or at time of disclosure, is unstated. Bitget’s own reserves, proof-of-reserves schedule, or insurance coverage for the loss are absent from the summary.
Attribution without evidence is a genre
Exchanges have a history of naming state actors after large outflows, often before forensic work is complete. The pattern serves a communications purpose: it frames the loss as an act of war rather than a custody failure. Whether this instance follows that pattern cannot be determined from the available text. The source does not quote a Bitget spokesperson, a security partner, or a government advisory.
What to watch
If Bitget publishes a post-mortem with signed messages, chain-analysis screenshots, or a law-enforcement reference number, the claim becomes verifiable. Until then, the $387.5 million figure rests entirely on the exchange’s say-so. The source provides no further detail.