Bitget chief executive Gracy Chen has said North Korea’s Lazarus Group drained about $80,000 in cryptocurrency from her personal MetaMask wallet roughly a year and a half ago, after attackers posed as a journalist and drew her into a fake Zoom interview. The personal loss is separate from the $387.5 million hack of Bitget’s hot and warm wallets, which the exchange disclosed on September 24, 2026.
Bitget is a centralized cryptocurrency exchange. The Lazarus Group is a hacking group widely linked to the government of the Democratic People’s Republic of Korea (DPRK), commonly known as North Korea. MetaMask is a self-custody crypto wallet, meaning the user, not an exchange, controls the funds.
How the Fake Interview Played Out
In remarks, Chen said the attackers “pretended to be a former journalist” from a major cryptocurrency media outlet. She said they first took control of that outlet’s official X account and used it to send her a direct message requesting an interview.
The attackers then used a compromised Telegram account to coordinate timing and topics with her public relations (PR) team and her assistant. Chen said the exchange appeared genuine. The session itself ran on a regular Zoom call, and she said that was when her wallet was compromised.
“I personally face the Lazarus group directly about one and a half years ago when my own Metamask wallet which where I lost about 80,000 worth of Ethereum or coins and some other cryptocurrencies,” Chen said, according to a transcript of her account.
She described the method as social engineering, a tactic that manipulates people rather than breaking technical systems. Chen has not named the media outlet that was impersonated. No law enforcement agency has publicly confirmed that the same operators carried out both her personal theft and the attack on Bitget.
Bitget’s User Protection Fund, a reserve set aside to cover customer losses, does not apply to the CEO’s personal wallet.
Inside the $387.5 Million Bitget Hack
Bitget’s systems flagged unauthorized transfers at 18:31 UTC (Coordinated Universal Time) on September 24, and the exchange first put the loss at about $351.6 million. On September 25, it raised the figure to about $387.5 million after adding Zcash (ZEC) and TRON transfers from the same window, and offered a 5% recovery bounty. Bitget said the revision did not reflect a second theft. The largest share of the stolen assets was about 103 million XRP, worth roughly $157 million in early estimates.
Chen said the attacker compromised a backend system in Bitget’s wallet infrastructure, spoofed transaction data, and triggered the exchange’s own authorization process. She said private keys were not stolen and cold wallets, which are kept offline, were not affected. Bitget has also said the attacker exploited a flaw in a third-party security product to obtain internal credentials.
Blockchain security firm SlowMist and cybersecurity firm Mandiant, both hired by Bitget, later said malicious activity on the third-party product dated to August 31, weeks before any funds moved. Chen has said IP addresses and on-chain patterns appear consistent with a DPRK-linked group. That attribution remains the exchange’s own assessment.
Withdrawals and the User Protection Fund
Bitget paused withdrawals but kept deposits and trading open. The User Protection Fund held more than $464 million at the time of the hack, and the exchange said it would cover the loss in full. In Chen’s September 30 update, the fund was back to about $309 million.
Under Bitget’s phased withdrawal schedule, Bitcoin (BTC) withdrawals resumed on September 28, Ether (ETH) on September 29, and Tether (USDT) on September 30. Withdrawals for remaining tokens, fiat currency, and peer-to-peer (P2P) trading are scheduled for October 2 at 08:00 UTC.
Tracing the Stolen Funds
Recovery efforts have so far captured only a small portion of the stolen assets. NEAR Intents, a cross-chain transaction network, said attackers tried to route more than $50 million through its system, but only about $503,000 was frozen. Cross-chain liquidity protocol THORChain declined Chen’s request to block wallets tied to the hacker.
On-chain investigator ZachXBT said about 2,700 ZEC, worth roughly $3.8 million, moved into Zcash’s Ironwood shielded pool, which hides transaction details. He also named five people he says are laundering funds for the alleged DPRK attackers.
Blockchain tracking tool MistTrack has flagged later flows through Wasabi CoinJoin, a privacy tool that mixes transactions from multiple users, as well as DAI stablecoin moving toward the Tron network. Issuer freezes have caught about $318,000 of those funds.
In a separate incident after the hack, Chen said scammers posing as a well-known investment firm approached her around September 28. She said she spotted the attempt by verifying with the firm’s leader through a different channel. That approach is unrelated to the earlier Zoom theft.
Also Read: Ostium $23.75M Hack Recovery: 3,321 Wallets Repaid, 345 LPs Face $1,000 Choice
