Bitget CEO Gracy Chen Reveals $80,000 Loss from Lazarus Group Cyber Attack

Why it matters
This incident reveals vulnerabilities in human-layer security that can have widespread implications for the cryptocurrency industry.
What happened (in 30 seconds)
- Gracy Chen, CEO of Bitget, disclosed a personal loss of approximately $80,000 due to a social engineering scam linked to North Korea's Lazarus Group.
- The attack involved hackers compromising a crypto media outlet's X account to impersonate journalists and conduct a fake interview.
- This incident coincided with a larger $387.5 million breach at Bitget, attributed to the same threat actor.
The context you actually need
- Lazarus Group is known for targeting cryptocurrency exchanges and executives through sophisticated social engineering tactics.
- High-profile crypto executives often engage with media, creating exploitable trust vectors when accounts are compromised.
- The attack on Chen involved multiple layers of deception, including compromised communication channels and a fake interview setup.
What's really happening
On September 25, 2026, Gracy Chen, the CEO of Bitget, publicly revealed a personal loss of approximately $80,000 due to a social engineering attack orchestrated by the notorious Lazarus Group, a North Korean state-sponsored hacking collective. This incident is not just a personal setback for Chen; it reflects a broader vulnerability within the cryptocurrency sector, particularly concerning human-layer security.
The attack began approximately 1.5 years prior to the disclosure when hackers compromised the X account of a major crypto media outlet. By impersonating journalists, the attackers initiated contact with Chen under the guise of conducting an interview. This initial contact was followed by further engagement with her PR team and assistant through compromised Telegram channels, which helped build credibility and trust. The culmination of this deception was a Zoom interview that ultimately led to the compromise of Chen's personal MetaMask wallet, resulting in the loss of around $80,000 in Ethereum and other assets.
This incident is particularly alarming given that it coincided with Bitget's detection of unauthorized transfers totaling $387.5 million from its hot and warm wallets. These transfers were executed using spoofed transaction data, indicating that the attackers had sophisticated methods to bypass security measures without compromising private keys. Chen noted that the operational signatures of this attack were consistent with previous Lazarus campaigns, suggesting a well-orchestrated effort to exploit vulnerabilities in the cryptocurrency ecosystem.
The implications of this incident extend beyond Chen's personal loss. Bitget activated emergency protocols, froze withdrawals, and referenced its $464 million User Protection Fund to cover user losses from the related breach. However, Chen's personal loss fell outside this coverage, highlighting a gap in protections for individual executives. Industry commentary has since focused on the need for enhanced human-factor security protocols, emphasizing that technical infrastructure alone is insufficient to safeguard against such sophisticated attacks.
As the cryptocurrency industry continues to grow, the need for robust security measures that encompass both technical and human elements becomes increasingly critical. This incident serves as a wake-up call for executives and organizations to reassess their security protocols and ensure that they are not only protecting their assets but also their reputations and personal finances.
Who feels it first (and how)
- Crypto Executives: Increased scrutiny on personal security measures and potential reputational damage.
- Crypto Exchanges: Heightened focus on security protocols and user protection funds.
- Investors: Concerns about the safety of their assets and the integrity of exchanges.
- Media Outlets: Need for enhanced security to protect against account compromises.
What to watch next
- Increased Security Measures: Watch for crypto exchanges to implement more stringent security protocols in response to this incident.
- Regulatory Scrutiny: Expect potential regulatory actions aimed at improving security standards across the cryptocurrency industry.
- Public Awareness Campaigns: Look for initiatives aimed at educating crypto executives and users about social engineering threats and protective measures.
The attack was linked to the Lazarus Group and involved sophisticated social engineering tactics.
Other crypto executives may face similar threats, prompting a shift in security practices across the industry.
The full extent of the impact on Bitget's operations and user trust remains to be seen.
Frequently Asked Questions
- Why it matters?
- This incident reveals vulnerabilities in human-layer security that can have widespread implications for the cryptocurrency industry.
- What happened (in 30 seconds)?
- Gracy Chen, CEO of Bitget, disclosed a personal loss of approximately $80,000 due to a social engineering scam linked to North Korea's Lazarus Group. The attack involved hackers compromising a crypto media outlet's X account to impersonate journalists and conduct a fake interview. This incident coincided with a larger $387.5 million breach at Bitget, attributed to the same threat actor.
- What's really happening?
- On September 25, 2026, Gracy Chen, the CEO of Bitget, publicly revealed a personal loss of approximately $80,000 due to a social engineering attack orchestrated by the notorious Lazarus Group, a North Korean state-sponsored hacking collective. This incident is not just a personal setback for Chen; it reflects a broader vulnerability within the cryptocurrency sector, particularly concerning human-layer security. The attack began approximately 1.5 years prior to the disclosure when hackers compro
- Who feels it first (and how)?
- Crypto Executives: Increased scrutiny on personal security measures and potential reputational damage. Crypto Exchanges: Heightened focus on security protocols and user protection funds. Investors: Concerns about the safety of their assets and the integrity of exchanges. Media Outlets: Need for enhanced security to protect against account compromises.
- What to watch next?
- Increased Security Measures: Watch for crypto exchanges to implement more stringent security protocols in response to this incident. Regulatory Scrutiny: Expect potential regulatory actions aimed at improving security standards across the cryptocurrency industry. Public Awareness Campaigns: Look for initiatives aimed at educating crypto executives and users about social engineering threats and protective measures.
Covers Bitcoin plus altcoin news, market updates, and educational resources.
"Bitcoin.com provides news, market data, and guides focused on Bitcoin and the wider crypto industry."
— A47 Editor
Bitget CEO Wants Thorchain to Block Hackers, but There’s a Catch
Gracy Chen, CEO of Bitget, has called for Thorchain to implement measures to block hackers following a significant security breach that resulted in unauthorized transfers totaling $352 million. This incident has raised serious concerns about the secu...
Curated tech headlines including AI stories.
"Influential aggregator surfacing the day’s top tech/AI links."
— A47 Editor
Bitget CEO Gracy Chen says she suspects North Korean attackers exploited a backend system used to process wallet transactions to drain $387M from the platform (Camila Grigera Naón/Fortune)
Bitget, a cryptocurrency exchange, has reported a significant security breach, with CEO Gracy Chen suspecting that North Korean attackers exploited a backend system to drain approximately $387 million from the platform. This incident follows the dete...
Real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors.
"Crypto News delivers real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors."
— A47 Editor
Bitget offers 5% bounty for freezing funds stolen in $351.6M attack
Bitget has announced a recovery bounty of 5% for freezing and recovering funds stolen in a recent security breach, initially estimated at $351.6 million. The attack involved unauthorized transfers affecting both hot and warm wallets, prompting the ex...
English-language digital publication covering business, politics, technology, and current affairs.
"The Arabian Post mixes original and syndicated-style coverage with a broad regional and global business-news orientation."
— A47 Editor
Bitget chief links $387.5 million breach to North Korea
Gracy Chen, the CEO of Bitget, has indicated that preliminary evidence suggests North Korean-linked hackers may be responsible for a security breach that resulted in the transfer of approximately $387.5 million in cryptocurrency from the exchange's w...
Research, news, and analysis on blockchain startups, DeFi, and regulations.
"Crypto Briefing provides research, news, and analysis on blockchain startups, DeFi, and crypto regulations with investor-focused coverage."
— A47 Editor
Bitget CEO Gracy Chen reveals $80K loss from fake interview scam tied to Lazarus Group
Gracy Chen, CEO of Bitget, disclosed an $80,000 loss resulting from a fake interview scam linked to the notorious Lazarus Group, highlighting vulnerabilities in the cryptocurrency sector. This incident emphasizes the urgent need for improved human-la...
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"CoinDesk is a well-established cryptocurrency and blockchain news provider, offering comprehensive insights, market data, and industry research."
— A47 Editor
Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gracy Chen says
Bitget, a cryptocurrency exchange, suffered a significant security breach resulting in unauthorized transfers totaling $352 million. CEO Gracy Chen stated that the hack occurred through spoofed transaction data rather than compromised private keys, r...
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"Cointelegraph is a leading crypto-focused media outlet known for timely news, analysis, and educational content related to blockchain and digital assets."
— A47 Editor
Bitget CEO suspects North Korea behind $352M hack, citing IP clues
Bitget CEO Gracy Chen has indicated that a preliminary investigation into a $352 million hack suggests North Korean involvement, citing IP addresses linked to a known DPRK hacking group. This revelation raises concerns about the security of cryptocur...
Curated tech headlines including AI stories.
"Influential aggregator surfacing the day’s top tech/AI links."
— A47 Editor
Bitget halts withdrawals after detecting unauthorized transfers from some hot and warm wallets, affecting ~$351.6M; CEO Gracy Chen says "user funds are safe" (Matthew Brockett/Bloomberg)
Bitget, a cryptocurrency exchange, has halted withdrawals after detecting unauthorized transfers from its hot and warm wallets, impacting approximately $351.6 million. CEO Gracy Chen reassured users that their funds remain safe despite the breach.
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"CoinDesk is a well-established cryptocurrency and blockchain news provider, offering comprehensive insights, market data, and industry research."
— A47 Editor
Crypto exchange Bitget says $352 million affected in a hack, claims user funds are 'safe'
Bitget, a cryptocurrency exchange, has confirmed a significant security breach resulting in unauthorized transfers totaling $352 million. The announcement came shortly after independent researchers detected unusual wallet movements, prompting CEO Gra...
Research, news, and analysis on blockchain startups, DeFi, and regulations.
"Crypto Briefing provides research, news, and analysis on blockchain startups, DeFi, and crypto regulations with investor-focused coverage."
— A47 Editor
Bitget confirms over $350M breach and temporarily pauses withdrawals
Bitget has confirmed a significant security breach involving unauthorized transfers totaling $351.6 million, leading to a temporary suspension of withdrawals. CEO Gracy Chen reassured users that customer funds remain protected despite the incident.