Code Defence Cyber security

Suspected North Korean threat actors steal 351M in Bitget exchange backend systems compromise

Cryptocurrency exchange security disclosures detail a major financial intrusion where state-sponsored threat actors breached internal wallet management infrastructure to authorize fraudulent high-value asset transfers. Incident response investigations link on-chain behavior and IP telemetry to North Korean cybercrime syndicates.

The incident resulted in the theft of 351.6 million dollars in digital assets across Ethereum, Binance Smart Chain, Arbitrum, and Avalanche networks. Threat actors compromised a critical backend transaction validation service within the exchange hot wallet architecture, leveraging administrative access to spoof internal transaction payloads and trick automated authorization gateways into approving outbound transfers. Mandiant and SlowMist have been engaged to conduct forensic triage and track exfiltrated funds across decentralized mixers.

Subverting core backend authorization microservices undermines internal control boundaries across financial platforms. When threat actors compromise internal validation daemons, adversaries can bypass cryptographic signing rules and execute unauthorized high-value transactions without raising perimeter network alarms.

– Audit internal microservice communication pathways and enforce mutual TLS authentication across automated transaction services.

– Implement multi-party computation MPC controls requiring out-of-band human authorization for high-volume asset movements.

– Inspect application server logs for unverified administrative session creations or anomalous RPC call invocations.

– Enforce continuous non-human identity auditing across internal cloud API endpoints and backend database services.

Financial platform infrastructure defense requires multi-tiered authorization controls and continuous zero-trust identity verification to ensure critical transaction services remain protected against state-sponsored backend subversion. #CodeDefence #Bitget #Mandiant #Cybercrime #NorthKorea #TraderTraitor #FinTech #CloudSecurity #IncidentResponse
/

Scroll to Top