Bitget CEO Gracy Chen Loses $80K to Lazarus Group Scam Amid Major Exchange Breach
Gracy Chen, the CEO of Bitget, has disclosed that she fell victim to a social engineering scam that resulted in a personal loss of approximately $80,000. The scam involved hackers impersonating journalists through a compromised account of a well-known crypto media outlet, a tactic reminiscent of operations by North Korea's Lazarus Group.
This personal loss comes in the wake of a larger security breach at Bitget, where the exchange reported unauthorized withdrawals totaling around $387.5 million from its wallets. The breach, detected on September 24, was characterized by attackers spoofing transaction data to redirect funds without compromising private keys.
Chen noted that her experience aligns with previous tactics employed by the Lazarus Group, which has a history of targeting crypto executives. The dual incidents highlight significant vulnerabilities in the crypto industry, particularly regarding human-layer attacks that exploit trust rather than technical infrastructure.
In response to the breach, Bitget has paused withdrawals and is utilizing its User Protection Fund, valued at over $464 million, to cover customer losses. However, Chen's personal loss is not covered by this fund, raising concerns about the effectiveness of existing security measures.
The ongoing investigation into the breach has seen the attacker move funds through Binance, withdrawing $1.23 million and consolidating assets in a wallet believed to be under their control. Law enforcement and cybersecurity firms are currently involved in tracing the stolen funds across multiple blockchain networks.
Updated 05:00 UTC
Latest Update on Bitget Breach
Bitget has confirmed a significant breach involving unauthorized transfers amounting to approximately $351.6 million from its hot and warm wallet infrastructure. The exchange has paused all withdrawals while it investigates the incident in collaboration with law enforcement and security firms.
Importantly, Bitget's cold wallets remain secure, and customer balances are reported to be accurate. The exchange has a User Protection Fund exceeding $464 million, which is intended to cover the losses incurred from this breach.
Bitget is actively working to identify and flag abnormal transfer addresses and has committed to providing a full incident report, including a root-cause analysis, within 24 hours.
While deposits and trading continue to be available, the pause on withdrawals raises concerns about user access to their assets during the ongoing investigation.
FAQ
What happened to Gracy Chen, the CEO of Bitget?
Gracy Chen fell victim to a social engineering scam that resulted in a personal loss of approximately $80,000, involving hackers impersonating journalists.
What was the larger security breach reported by Bitget?
Bitget reported unauthorized withdrawals totaling around $387.5 million from its wallets due to a security breach detected on September 24.
How did the attackers manage to redirect funds during the breach?
The attackers spoofed transaction data to redirect funds without compromising private keys, indicating a sophisticated method of attack.
What measures is Bitget taking in response to the breach?
Bitget has paused withdrawals and is utilizing its User Protection Fund, valued at over $464 million, to cover customer losses.
Are Gracy Chen's personal losses covered by Bitget's User Protection Fund?
No, Gracy Chen's personal loss of $80,000 is not covered by the User Protection Fund, raising concerns about the effectiveness of existing security measures.
Comments
Comments are moderated before publish.
No comments yet — be the first.