Trending

    Bitget CEO Gracy Chen Reveals $80,000 Loss from Lazarus Group Social Engineering Attack

    Section editor: ·High3 articles covering this·3 news sources·Updated 2 hours ago·World
    Share:
    Infographic showing the timeline of Bitget's breach and Gracy Chen's social engineering attack.

    Why it matters

    The incident highlights vulnerabilities in both individual and institutional security within the cryptocurrency sector, raising concerns about the effectiveness of current protective measures.

    What happened (in 30 seconds)

    • Gracy Chen, CEO of Bitget, disclosed a personal loss of $80,000 due to a social engineering scam involving a fake journalist interview.
    • The attack was linked to North Korea's Lazarus Group, which also executed a larger breach of Bitget's wallets, totaling $387.5 million.
    • Bitget has activated its User Protection Fund to cover user losses from the institutional breach, but Chen's personal loss is not covered.

    The context you actually need

    • Lazarus Group has a history of targeting cryptocurrency exchanges and executives through sophisticated social engineering tactics.
    • The attack on Bitget involved unauthorized transfers executed via spoofed transaction data rather than stolen private keys, indicating a new level of sophistication.
    • Crypto executives often engage with media, creating opportunities for impersonation via compromised verified accounts on platforms like X (formerly Twitter).

    What's really happening

    On September 24, 2026, Bitget experienced a significant breach, with unauthorized transfers from its hot and warm wallets totaling approximately $387.5 million. This breach was executed through spoofed transaction data, a method that bypassed the need for stolen private keys, indicating a shift in the tactics employed by cybercriminals. The following day, CEO Gracy Chen revealed that she had fallen victim to a separate social engineering attack, losing $80,000 from her personal wallet. This attack involved hackers compromising the X account of a crypto media outlet to arrange a fake interview, which ultimately led to the drainage of her wallet.

    Chen attributed both incidents to the Lazarus Group, citing technical indicators such as IP addresses and on-chain signatures that matched previous operations linked to the group. The Lazarus Group, a North Korean state-sponsored hacking collective, has a documented history of targeting cryptocurrency exchanges and executives, often employing sophisticated social engineering and supply-chain attacks. Their previous operations include the February 2025 Bybit hack, which exceeded $1.4 billion.

    The implications of these attacks are profound. They not only expose vulnerabilities in institutional infrastructure but also highlight the need for enhanced security measures at the individual executive level. The cryptocurrency sector is particularly susceptible to such attacks due to the high value of assets and the frequent interactions between executives and media. As Bitget activated its $464 million User Protection Fund to cover user losses from the institutional breach, Chen's personal loss fell outside this coverage, raising questions about the adequacy of existing protective measures for individuals.

    The incident has prompted Bitget to suspend withdrawals while maintaining deposits and trading, with customer balances confirmed intact. However, the scrutiny of exchange security protocols has intensified, with comparisons drawn to prior Lazarus operations against platforms like Bybit. Chen's public call for enhanced industry focus on human-layer security reflects a growing recognition that the human element remains a critical vulnerability in the cybersecurity landscape.

    Who feels it first (and how)

    • Crypto Executives: Increased scrutiny on personal security measures and potential reputational damage.
    • Cryptocurrency Exchanges: Heightened pressure to improve security protocols and protect user assets.
    • Investors and Traders: Concerns over the safety of their assets and the reliability of exchanges.
    • Media Outlets: Need for enhanced verification processes to prevent impersonation and misinformation.

    What to watch next

    • Law Enforcement Investigations: Ongoing investigations into the breach may reveal more about the tactics used and potential vulnerabilities in the sector.
    • Market Reactions: Watch for shifts in user trust and trading behavior on exchanges following this incident.
    • Security Protocol Enhancements: Increased focus on human-layer security measures across the cryptocurrency industry could emerge as a response to this attack.
    Known:

    The attack was linked to the Lazarus Group, a North Korean state-sponsored hacking collective.

    Likely:

    Increased scrutiny and regulatory pressure on cryptocurrency exchanges to enhance security measures.

    Unclear:

    The full extent of the impact on user trust and trading behavior in the aftermath of the breach.

    Frequently Asked Questions

    Why it matters?
    The incident highlights vulnerabilities in both individual and institutional security within the cryptocurrency sector, raising concerns about the effectiveness of current protective measures.
    What happened (in 30 seconds)?
    Gracy Chen, CEO of Bitget, disclosed a personal loss of $80,000 due to a social engineering scam involving a fake journalist interview. The attack was linked to North Korea's Lazarus Group, which also executed a larger breach of Bitget's wallets, totaling $387.5 million. Bitget has activated its User Protection Fund to cover user losses from the institutional breach, but Chen's personal loss is not covered.
    What's really happening?
    On September 24, 2026, Bitget experienced a significant breach, with unauthorized transfers from its hot and warm wallets totaling approximately $387.5 million. This breach was executed through spoofed transaction data, a method that bypassed the need for stolen private keys, indicating a shift in the tactics employed by cybercriminals. The following day, CEO Gracy Chen revealed that she had fallen victim to a separate social engineering attack, losing $80,000 from her personal wallet. This atta
    Who feels it first (and how)?
    Crypto Executives: Increased scrutiny on personal security measures and potential reputational damage. Cryptocurrency Exchanges: Heightened pressure to improve security protocols and protect user assets. Investors and Traders: Concerns over the safety of their assets and the reliability of exchanges. Media Outlets: Need for enhanced verification processes to prevent impersonation and misinformation.
    What to watch next?
    Law Enforcement Investigations: Ongoing investigations into the breach may reveal more about the tactics used and potential vulnerabilities in the sector. Market Reactions: Watch for shifts in user trust and trading behavior on exchanges following this incident. Security Protocol Enhancements: Increased focus on human-layer security measures across the cryptocurrency industry could emerge as a response to this attack.
    3 Articles
    Crypto Briefing

    Bitget CEO Gracy Chen reveals $80K loss from fake interview scam tied to Lazarus Group

    Gracy Chen, CEO of Bitget, disclosed an $80,000 loss resulting from a fake interview scam linked to the notorious Lazarus Group, highlighting vulnerabilities in the cryptocurrency sector. This incident emphasizes the urgent need for improved human-la...

    CoinDesk

    Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gracy Chen says

    Bitget, a cryptocurrency exchange, suffered a significant security breach resulting in unauthorized transfers totaling $352 million. CEO Gracy Chen stated that the hack occurred through spoofed transaction data rather than compromised private keys, r...

    Cointelegraph

    Bitget CEO suspects North Korea behind $352M hack, citing IP clues

    Bitget CEO Gracy Chen has indicated that a preliminary investigation into a $352 million hack suggests North Korean involvement, citing IP addresses linked to a known DPRK hacking group. This revelation raises concerns about the security of cryptocur...