【Bitget $350 Million Stolen Case Points to Lazarus Group, With XRP Funds Path Intersecting】

Bitget recently suffered the theft of around $350 million in XRP and related cross-chain fund paths, which were monitored by on-chain sleuth Specter. The activity directly intersects with the AFX attack case earlier this July, strongly pointing to the North Korean hacker group Lazarus Group.

The attack method shows that the hackers penetrated key backend systems, using forged transaction data to trick internal authorized transfers, without compromising private keys. The exchange fully covered the losses using user protection funds totaling over $460 million, but the specific “network access entry point” is still under investigation.

Compared with Lazarus’ historical modus operandi, this incident closely matches the themes of “deception of authorization” and “rapid fund aggregation.” The hackers controlled the backend and used a counterfeit dataset—one that appeared normal in the approval UI while being swapped on-chain—to bypass authorization. Subsequently, the funds were monetized via cross-chain bridges and OTC channels, exhibiting characteristics of a large organized group. Notably, although Bybit was previously breached through an “external signing service,” this time Bitget appears to be pointing to its “own wallet backend.” A final determination still awaits the official technical report.

This incident may further heighten market concerns about the backend security of centralized exchanges and the XRP cross-chain money-laundering routes. Going forward, attention should be paid to the official technical disclosures regarding the network-access method, as well as the final tracing results for the flow of funds tied to Lazarus Group.

$XRP