Bitget CEO says $388M hack traced to third-party security flaw

Bitget CEO says $388M hack traced to third-party security flaw

N
News Editor
2026-09-28 14:46:21
Bitget CEO Gracy Chen said the exchange’s recent $388 million exploit was caused by a vulnerability in a third-party security product, which let the attacker obtain high-level internal credentials and send fraudulent withdrawal commands. Chen said Bitget’s private keys were not compromised and its cold wallets were not affected. The exchange said it has fixed the flaw and tightened withdrawal controls by limiting internal access, adding independent verification for withdrawals and stepping up monitoring for unusual activity. The attack was detected on Sept. 24 after unauthorized transfers were spotted from several hot wallets, prompting a temporary withdrawal suspension. Bitget initially estimated that about $352 million in assets had been affected. Chen also said some stolen assets have been frozen with help from other industry participants, but the exchange has not yet disclosed the total amount recovered or frozen. On the question of a possible North Korea link, she said earlier comments were based on preliminary indicators that are still under review, with Mandiant and SlowMist supporting an independent forensic investigation.

Bitget CEO Gracy Chen said the exchange’s recent $388 million exploit stemmed from a vulnerability in a third-party security product that allowed the attacker to obtain “high-level internal credentials.”

In comments to Cointelegraph, Chen said the attacker used those credentials to issue fraudulent withdrawal commands. She said Bitget’s private keys were not compromised, and its cold wallets were not affected.

Bitget said it has since addressed the security flaw and tightened its withdrawal controls. The measures include restricting internal access, adding independent verification for withdrawals and increasing monitoring for unusual activity.

The attack took place on Sept. 24, when Bitget detected unauthorized transfers from several of its hot wallets and temporarily suspended withdrawals. The exchange initially estimated that about $352 million in assets had been affected.

Bitget has not released recovery totals

The exchange has not disclosed how much of the stolen cryptocurrency has been recovered or frozen. Chen said some assets have been frozen with help from other industry participants, but Bitget will release a total only after verifying the amounts.

Bitget had previously called on THORChain, a protocol used to swap assets across blockchains, to refuse services to addresses linked to the attack.

The exchange also said it is not asking THORChain to halt its network while it tries to stop the stolen assets from being moved. THORChain has said it cannot selectively blacklist individual addresses.

“We understand that THORChain operates as a decentralized protocol and has said that it cannot selectively blacklist individual addresses. We respect the technical constraints of different networks and are not asking any protocol to take actions that are not technically possible,” Chen said.

North Korea suspicion still under review

Chen also addressed Bitget’s earlier suspicion that North Korea may have been behind the attack.

“What was shared previously was based on preliminary indicators identified during the investigation,” Chen said.

“Those indicators are still being assessed. Mandiant and SlowMist are supporting the independent forensic investigation, and that work is ongoing. We will share further findings as they are verified,” she added.

Cointelegraph said the story included additional reporting by Helen Partz.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.