AIO APEX

Crypto exchanges keep building bigger insurance funds. North Korea keeps draining them anyway.

Share:
Crypto exchanges keep building bigger insurance funds. North Korea keeps draining them anyway.

When Bitget disclosed on September 24 that roughly $351.6 million had been drained from its platform, CEO Gracy Chen moved quickly to reassure users: the loss would be fully covered by the exchange's User Protection Fund, which holds more than $464 million. That's the correct response, and Bitget deserves credit for actually having a fund large enough to matter. But look at the arithmetic underneath the reassurance: a single attack is projected to consume roughly 76% of the fund's entire balance. This wasn't a fund absorbing a routine loss. It was a fund nearly wiped out by one incident.

That's the uncomfortable pattern in crypto exchange security right now. Insurance funds and proof-of-reserves attestations have become standard industry practice, marketed as evidence that platforms take custody seriously. They are, in a narrow sense, real — Bitget's fund is genuinely backed by real assets, and the company says it holds over $1 billion in proprietary capital it will use to replenish the fund if needed. But the scale of individual attacks has grown to match, and in some cases exceed, the scale of the defenses built to absorb them.

Investigators tracing the Bitget breach found IP addresses linked to VPN services previously associated with North Korean state-sponsored hacking groups. If confirmed, it fits an unmistakable pattern: North Korea's Lazarus Group and its affiliated units have stolen more than $6 billion in cryptocurrency since 2017, according to blockchain analytics firms tracking DPRK-linked wallets. In just the first half of 2026, North Korean-linked actors were responsible for an estimated 55-66% of all crypto theft — a concentration of capability that has turned a handful of state-backed hacking teams into the single biggest threat to centralized exchange security worldwide, more dangerous in aggregate than the entire rest of the criminal ecosystem combined.

The technical details of the Bitget attack matter, because they show these aren't smash-and-grab jobs. According to Bitget's own account, attackers compromised a critical backend system inside the wallet infrastructure, used that access to spoof transaction data, and triggered the exchange's own authorization process to move funds out — essentially convincing the system's internal controls that a fraudulent withdrawal was legitimate. That's not a stolen password or a phishing email. It's a sophisticated, patient compromise of infrastructure that most users assume is untouchable specifically because it sits behind the parts of an exchange that face outward.

This is where proof-of-reserves attestations reveal their limits. A proof-of-reserves check confirms that an exchange holds the assets it claims to hold — at the moment of the snapshot. It says nothing about whether the backend systems moving those assets are secure, and nothing about what happens in the hours after a breach, when an exchange has to decide in real time whether to freeze withdrawals, how much of the loss to socialize across the insurance fund, and how transparent to be with users mid-crisis. Bitget's fast, public acknowledgment and commitment to full reimbursement is actually the exception in an industry where slower or more evasive responses have historically been the norm.

There's a regulatory wrinkle worth separating out clearly here: the GENIUS Act, signed into law in July 2025, established federal licensing and strict 1:1 reserve requirements — but specifically for USD-backed payment stablecoin issuers, not for the custody practices of centralized exchanges like Bitget. Exchange-level security, wallet infrastructure, and insurance fund adequacy remain governed mostly by each platform's own internal choices and by jurisdiction-specific licensing regimes that vary enormously in rigor. In other words, the part of crypto infrastructure most frequently and successfully attacked by nation-state actors is also the part with the least standardized regulatory floor.

What this means for anyone holding assets on a centralized exchange: an insurance fund is a genuinely valuable backstop, but its existence tells you nothing about its adequacy relative to the threat a platform actually faces. Before treating any exchange's protection fund as a reason for confidence, look at three things: the fund's size relative to total assets under custody (not just its headline dollar figure), whether the exchange has faced and survived a prior breach without socializing losses onto users, and how quickly and transparently it communicated during its last incident. Bitget passed that last test. Whether its fund can survive a second attack of similar scale, without depleting the $1 billion in proprietary capital it's promised to draw on, is the question worth watching.

Share:
Crypto exchanges keep building bigger insurance funds. North Korea keeps draining them anyway. | AIO APEX