Trending

    Bitget CEO Gracy Chen Reveals $80,000 Loss from Lazarus Group Cyber Attack

    Section editor: ·Moderate10 articles covering this·7 news sources·Updated 2 hours ago·World
    Share:
    Infographic showing the layers of deception in Gracy Chen's social engineering attack, highlighting compromised channels and asset flow.

    Why it matters

    This incident reveals vulnerabilities in human-layer security that can have widespread implications for the cryptocurrency industry.

    What happened (in 30 seconds)

    • Gracy Chen, CEO of Bitget, disclosed a personal loss of approximately $80,000 due to a social engineering scam linked to North Korea's Lazarus Group.
    • The attack involved hackers compromising a crypto media outlet's X account to impersonate journalists and conduct a fake interview.
    • This incident coincided with a larger $387.5 million breach at Bitget, attributed to the same threat actor.

    The context you actually need

    • Lazarus Group is known for targeting cryptocurrency exchanges and executives through sophisticated social engineering tactics.
    • High-profile crypto executives often engage with media, creating exploitable trust vectors when accounts are compromised.
    • The attack on Chen involved multiple layers of deception, including compromised communication channels and a fake interview setup.

    What's really happening

    On September 25, 2026, Gracy Chen, the CEO of Bitget, publicly revealed a personal loss of approximately $80,000 due to a social engineering attack orchestrated by the notorious Lazarus Group, a North Korean state-sponsored hacking collective. This incident is not just a personal setback for Chen; it reflects a broader vulnerability within the cryptocurrency sector, particularly concerning human-layer security.

    The attack began approximately 1.5 years prior to the disclosure when hackers compromised the X account of a major crypto media outlet. By impersonating journalists, the attackers initiated contact with Chen under the guise of conducting an interview. This initial contact was followed by further engagement with her PR team and assistant through compromised Telegram channels, which helped build credibility and trust. The culmination of this deception was a Zoom interview that ultimately led to the compromise of Chen's personal MetaMask wallet, resulting in the loss of around $80,000 in Ethereum and other assets.

    This incident is particularly alarming given that it coincided with Bitget's detection of unauthorized transfers totaling $387.5 million from its hot and warm wallets. These transfers were executed using spoofed transaction data, indicating that the attackers had sophisticated methods to bypass security measures without compromising private keys. Chen noted that the operational signatures of this attack were consistent with previous Lazarus campaigns, suggesting a well-orchestrated effort to exploit vulnerabilities in the cryptocurrency ecosystem.

    The implications of this incident extend beyond Chen's personal loss. Bitget activated emergency protocols, froze withdrawals, and referenced its $464 million User Protection Fund to cover user losses from the related breach. However, Chen's personal loss fell outside this coverage, highlighting a gap in protections for individual executives. Industry commentary has since focused on the need for enhanced human-factor security protocols, emphasizing that technical infrastructure alone is insufficient to safeguard against such sophisticated attacks.

    As the cryptocurrency industry continues to grow, the need for robust security measures that encompass both technical and human elements becomes increasingly critical. This incident serves as a wake-up call for executives and organizations to reassess their security protocols and ensure that they are not only protecting their assets but also their reputations and personal finances.

    Who feels it first (and how)

    • Crypto Executives: Increased scrutiny on personal security measures and potential reputational damage.
    • Crypto Exchanges: Heightened focus on security protocols and user protection funds.
    • Investors: Concerns about the safety of their assets and the integrity of exchanges.
    • Media Outlets: Need for enhanced security to protect against account compromises.

    What to watch next

    • Increased Security Measures: Watch for crypto exchanges to implement more stringent security protocols in response to this incident.
    • Regulatory Scrutiny: Expect potential regulatory actions aimed at improving security standards across the cryptocurrency industry.
    • Public Awareness Campaigns: Look for initiatives aimed at educating crypto executives and users about social engineering threats and protective measures.
    Known:

    The attack was linked to the Lazarus Group and involved sophisticated social engineering tactics.

    Likely:

    Other crypto executives may face similar threats, prompting a shift in security practices across the industry.

    Unclear:

    The full extent of the impact on Bitget's operations and user trust remains to be seen.

    Frequently Asked Questions

    Why it matters?
    This incident reveals vulnerabilities in human-layer security that can have widespread implications for the cryptocurrency industry.
    What happened (in 30 seconds)?
    Gracy Chen, CEO of Bitget, disclosed a personal loss of approximately $80,000 due to a social engineering scam linked to North Korea's Lazarus Group. The attack involved hackers compromising a crypto media outlet's X account to impersonate journalists and conduct a fake interview. This incident coincided with a larger $387.5 million breach at Bitget, attributed to the same threat actor.
    What's really happening?
    On September 25, 2026, Gracy Chen, the CEO of Bitget, publicly revealed a personal loss of approximately $80,000 due to a social engineering attack orchestrated by the notorious Lazarus Group, a North Korean state-sponsored hacking collective. This incident is not just a personal setback for Chen; it reflects a broader vulnerability within the cryptocurrency sector, particularly concerning human-layer security. The attack began approximately 1.5 years prior to the disclosure when hackers compro
    Who feels it first (and how)?
    Crypto Executives: Increased scrutiny on personal security measures and potential reputational damage. Crypto Exchanges: Heightened focus on security protocols and user protection funds. Investors: Concerns about the safety of their assets and the integrity of exchanges. Media Outlets: Need for enhanced security to protect against account compromises.
    What to watch next?
    Increased Security Measures: Watch for crypto exchanges to implement more stringent security protocols in response to this incident. Regulatory Scrutiny: Expect potential regulatory actions aimed at improving security standards across the cryptocurrency industry. Public Awareness Campaigns: Look for initiatives aimed at educating crypto executives and users about social engineering threats and protective measures.
    10 Articles
    Bitcoin.com

    Bitget CEO Wants Thorchain to Block Hackers, but There’s a Catch

    Gracy Chen, CEO of Bitget, has called for Thorchain to implement measures to block hackers following a significant security breach that resulted in unauthorized transfers totaling $352 million. This incident has raised serious concerns about the secu...

    Techmeme

    Bitget CEO Gracy Chen says she suspects North Korean attackers exploited a backend system used to process wallet transactions to drain $387M from the platform (Camila Grigera Naón/Fortune)

    Bitget, a cryptocurrency exchange, has reported a significant security breach, with CEO Gracy Chen suspecting that North Korean attackers exploited a backend system to drain approximately $387 million from the platform. This incident follows the dete...

    11 hours ago
    Read Full Article
    Crypto News

    Bitget offers 5% bounty for freezing funds stolen in $351.6M attack

    Bitget has announced a recovery bounty of 5% for freezing and recovering funds stolen in a recent security breach, initially estimated at $351.6 million. The attack involved unauthorized transfers affecting both hot and warm wallets, prompting the ex...

    18 hours ago
    Read Full Article
    The Arabian Post

    Bitget chief links $387.5 million breach to North Korea

    Gracy Chen, the CEO of Bitget, has indicated that preliminary evidence suggests North Korean-linked hackers may be responsible for a security breach that resulted in the transfer of approximately $387.5 million in cryptocurrency from the exchange's w...

    20 hours ago
    Read Full Article
    Crypto Briefing

    Bitget CEO Gracy Chen reveals $80K loss from fake interview scam tied to Lazarus Group

    Gracy Chen, CEO of Bitget, disclosed an $80,000 loss resulting from a fake interview scam linked to the notorious Lazarus Group, highlighting vulnerabilities in the cryptocurrency sector. This incident emphasizes the urgent need for improved human-la...

    CoinDesk

    Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gracy Chen says

    Bitget, a cryptocurrency exchange, suffered a significant security breach resulting in unauthorized transfers totaling $352 million. CEO Gracy Chen stated that the hack occurred through spoofed transaction data rather than compromised private keys, r...

    Cointelegraph

    Bitget CEO suspects North Korea behind $352M hack, citing IP clues

    Bitget CEO Gracy Chen has indicated that a preliminary investigation into a $352 million hack suggests North Korean involvement, citing IP addresses linked to a known DPRK hacking group. This revelation raises concerns about the security of cryptocur...

    Techmeme

    Bitget halts withdrawals after detecting unauthorized transfers from some hot and warm wallets, affecting ~$351.6M; CEO Gracy Chen says "user funds are safe" (Matthew Brockett/Bloomberg)

    Bitget, a cryptocurrency exchange, has halted withdrawals after detecting unauthorized transfers from its hot and warm wallets, impacting approximately $351.6 million. CEO Gracy Chen reassured users that their funds remain safe despite the breach.

    CoinDesk

    Crypto exchange Bitget says $352 million affected in a hack, claims user funds are 'safe'

    Bitget, a cryptocurrency exchange, has confirmed a significant security breach resulting in unauthorized transfers totaling $352 million. The announcement came shortly after independent researchers detected unusual wallet movements, prompting CEO Gra...

    Crypto Briefing

    Bitget confirms over $350M breach and temporarily pauses withdrawals

    Bitget has confirmed a significant security breach involving unauthorized transfers totaling $351.6 million, leading to a temporary suspension of withdrawals. CEO Gracy Chen reassured users that customer funds remain protected despite the incident.