North Korea Is Rewriting the Crypto Hack Playbook — Again
BitGet lost $387 million to what it calls a North Korean hack. But the more alarming story is a second theft from Korean retail wallet provider DCENT just days later — a sign that Pyongyang's cybercrime apparatus is diversifying its targets beyond exchanges.
The Hack Nobody Was Waiting For
BitGet, the fifth-largest cryptocurrency exchange by trading volume, confirmed on September 26 that roughly $387.5 million in digital assets had been siphoned from its wallets. The timing — early morning on September 25, at 3:31 a.m. local — was classic. And so was the attribution: BitGet CEO Gracie Chen pointed directly to North Korea, citing VPN IP addresses consistent with those the regime has used in previous operations.
The stolen assets tell a specific story. XRP led the take with 129 million tokens removed, followed by 31,890 Ethereum, $34.75 million in USDT, $21.05 million in USDC, and 12,719 BNB. The funds were then converted into Ethereum — a move that points to sophistication and familiarity with chain-hopping techniques well-documented in prior North Korean blockchain thefts.
Bitcoin, already sliding on macro headwinds, dipped below $85,000 to around $83,967 shortly after the news broke — the lowest it has traded since late January. The drop was partly symptomatic; the hack landed on top of an already weakening sentiment, compounded by the U.S. Congress failing to pass the Clarity Act, which had offered a glimmer of regulatory clarity for institutional players.
But the BitGet breach is not the full picture. And that is where the real concern lies.
The Second Hit Was Even More Alarming
Just days before the BitGet attack, on September 16, a Korean domestic wallet service called DCENT reported abnormal outflows of more than 10 million XRP — valued at roughly 20 billion won, or about $15 million at the time. DCENT is not an exchange. It is a non-custodial wallet provider, meaning it stores private keys for individual users, not pooled exchange reserves.
That distinction matters enormously.
Historically, North Korean cyber units like the Lazarus Group have targeted centralized exchanges — hot wallets holding customer funds in custody. These are high-value, single-point-of-failure targets. But the DCENT intrusion signals something new: Pyongyang’s operators are now probing the infrastructure that retail users themselves rely on. A successful breach of a wallet provider does not require compromising an exchange’s cold storage or internal controls. It requires only that users install a compromised update, visit a phishing page, or fall for social engineering disguised as a wallet security notice.
Two attacks in ten days, both involving XRP, both pointing toward North Korean tradecraft, both hitting Korean-linked entities — this is not coincidence. It is a pattern.
Why XRP Keeps Getting Hit
XRP appears in both incidents with outsized frequency. In the BitGet breach, it accounted for the largest volume of stolen tokens by count. In the DCENT attack, it was the primary asset removed. This is not random. XRP’s relatively high per-token value, its liquidity on major decentralized exchanges, and its cross-chain bridge options make it an efficient vehicle for converting stolen funds into something tradable or mixable.
North Korean operatives have long understood the practical advantages of moving quickly through XRP’s settlement network, where transactions finality takes seconds rather than the minutes or hours required by Ethereum or Bitcoin. Speed matters when you are fleeing an on-chain audit trail.
Who Wins, Who Loses
The immediate losers are BitGet’s users and DCENT’s customers, both of whom face uncertainty about whether their assets will be recovered. Neither company has offered full compensation guarantees yet. BitGet suspended withdrawals temporarily while it traced the flow of funds.
North Korea wins, obviously. The regime’s Cyber Warfare Command has long treated cryptocurrency theft as a legitimate revenue stream. An estimated $2 billion to $3 billion is thought to flow annually through these operations, funding programs that international sanctions explicitly prohibit. Each successful heist is a direct violation of UN Security Council resolutions and a boost to a regime that otherwise faces severe financial isolation.
Regulators lose credibility. Every high-profile breach reinforces the argument that virtual assets remain an unstable layer of global finance — an argument that policymakers in Washington, Seoul, and Brussels are eager to hear, even as they simultaneously push for broader crypto adoption through frameworks like the Clarity Act.
What Happens Next
BitGet’s decision to publicly name North Korea is significant. Most exchanges prefer to keep such attributions quiet, fearing reputational damage from association with state-sponsored crime. BitGet went public — likely because the evidence was clear and the geopolitical timing made silence counterproductive. The U.S. Treasury’s Office of Foreign Assets Control has previously sanctioned North Korean blockchain addresses linked to Lazarus Group activity. Expect additional designations in coming weeks.
Seoul will face pressure to act. The DCENT breach, even if smaller in dollar terms, occurred on home soil and involved a domestically regulated entity. The Financial Services Commission and the Korea Exchange have hinted at stricter custody rules for virtual asset service providers, and this incident will accelerate those discussions.
For retail traders, the practical takeaway is sobering. The BitGet hack exploited a centralized exchange vulnerability. The DCENT hack exploited a wallet-level one. Between them, they cover the two most common entry points for crypto theft. Cold storage remains the only reliable hedge — and even then, it depends on how securely a user manages their own keys.
The broader implication extends beyond any single exchange or wallet provider. North Korea’s cyber units have demonstrated adaptability, pivoting from bank heists to cryptocurrency, and now from exchanges to user-facing infrastructure. The next target is not necessarily another exchange. It could be a cross-chain bridge, a popular DeFi protocol, or a mobile wallet app downloaded by millions.
The regime has spent over a decade refining this playbook. The question is no longer whether it will strike again, but what kind of infrastructure it targets next — and whether the market’s security postures are keeping pace.