Bitget2026-09-28 14:46:21Bitget CEO says $388M hack traced to third-party security flawBitget CEO Gracy Chen said the exchange’s recent $388 million exploit was caused by a vulnerability in a third-party security product, which let the attacker obtain high-level internal credentials and send fraudulent withdrawal commands. Chen said Bitget’s private keys were not compromised and its cold wallets were not affected. The exchange said it has fixed the flaw and tightened withdrawal controls by limiting internal access, adding independent verification for withdrawals and stepping up monitoring for unusual activity. The attack was detected on Sept. 24 after unauthorized transfers were spotted from several hot wallets, prompting a temporary withdrawal suspension. Bitget initially estimated that about $352 million in assets had been affected. Chen also said some stolen assets have been frozen with help from other industry participants, but the exchange has not yet disclosed the total amount recovered or frozen. On the question of a possible North Korea link, she said earlier comments were based on preliminary indicators that are still under review, with Mandiant and SlowMist supporting an independent forensic investigation.20
Bitget2026-09-28 08:33:16Bitget executive says first security incident in eight years stemmed from third-party flaw, withdrawals are resumingBitget Greater China head Xie Jiayin addressed community concerns in a recent livestream, saying the platform’s latest incident was the first security crisis in Bitget’s eight-year history. He said the exchange had previously withstood multiple cyberattack attempts while keeping user asset security as its top priority. According to Xie, Bitget’s tracing work found that the case was a special attack targeting the supply chain of third-party security software. The attacker used a vulnerability in a third-party product to obtain internal network credentials. He said private keys were not leaked and assets in cold wallets were not affected. Bitget has started independent reviews with security firms Mandiant and SlowMist, Xie said. The company also plans to strengthen monitoring and management standards for third-party components. He added that withdrawals on the platform are being restored step by step as recovery work continues after the incident.20
Bitget2026-09-28 08:31:56Bitget says private keys were not exposed in its first security crisis, launches independent reviewBitget Greater China head Xie Jiayin addressed community concerns in a recent livestream, calling the incident the first security crisis in the exchange’s eight-year history. He said Bitget has prioritized user asset security since its founding and has maintained a long-term operating record while fending off multiple cyberattack attempts. According to Xie, the incident was traced to a targeted attack on the supply chain of third-party security software. The attacker used a vulnerability in a third-party product to obtain internal network credentials. Bitget said its private keys were not leaked and assets held in cold wallets were not affected. The exchange has brought in security firms Mandiant and SlowMist to conduct an independent review. It also plans to upgrade monitoring and management standards for third-party components. Xie said Bitget is working on a full recovery from the incident and will continue technical and system upgrades aimed at improving security standards.20
Bitget2026-09-26 04:30:57Bitget sets phased withdrawal resumption after fixing security flawBitget said on Sept. 26 that it has confirmed and fixed the vulnerability tied to a security incident discovered on Sept. 24, and will resume withdrawals in phases after completing additional security checks. Mandiant, the Google-owned cybersecurity firm, and SlowMist are assisting with the investigation. According to the exchange, the withdrawal suspension was a temporary security measure and did not affect the availability of user assets or account balances. Bitget also said its protection fund will cover the financial impact caused by the platform-level incident. The exchange added that the situation is now under control, unauthorized transfers will not happen again, and trading and deposit services remain operational. Its withdrawal reopening schedule starts with BTC on Sept. 28 at 08:00 UTC, followed by ETH on several networks on Sept. 29, USDT on multiple networks on Sept. 30, and other tokens, fiat, and peer-to-peer trading on Oct. 2.00
Bitget2026-09-26 04:06:23Bitget says flaw tied to Sept. 24 security incident has been fixed, withdrawals to resume in stagesBitget said the vulnerability linked to a security incident discovered on Sept. 24 has been identified and fixed, and the exchange will restore withdrawals in phases after completing additional security checks. Google-owned cybersecurity firm Mandiant and blockchain security company SlowMist are assisting with the investigation. According to the schedule released by Bitget, BTC withdrawals on the Bitcoin network are set to resume at 8:00 UTC on Sept. 28. ETH withdrawals on Ethereum, BNB Smart Chain, Arbitrum, Base, and Optimism will follow at 8:00 UTC on Sept. 29. USDT withdrawals on Ethereum, BNB Smart Chain, Solana, and TRON are scheduled for 8:00 UTC on Sept. 30, while other tokens, fiat, and peer-to-peer trading services are set for Oct. 2 at 8:00 UTC. Bitget said the withdrawal suspension was a temporary security measure and was unrelated to the availability of user assets. The exchange added that account balances were unaffected, its protection fund will cover the financial impact caused by this platform-level incident, and trading and deposit services remain operational. Users do not need to take action in advance, and the exchange said final reopening details will be announced through its platform and official channels.00
Bitget2026-09-26 01:12:28Bitget says $357 million was moved without authorization as Elliptic points to North Korea-linked hackersCrypto exchange Bitget said it detected unauthorized asset transfers on Thursday, with losses reaching about $357 million across multiple tokens. Blockchain analytics firm Elliptic said the laundering pattern seen after the theft, along with overlaps in on-chain addresses, points to TraderTraitor, a hacking group it links to North Korea. The report said the attackers quickly swapped tokens and moved funds across chains, and that some of the addresses were connected to earlier hacks, including last year’s record $1.5 billion Bybit theft. Elliptic added that North Korea-linked groups have been tied to more than 50 digital-asset security incidents this year, with roughly $1.2 billion stolen in total. Bitget said it suspended withdrawals after the incident and stressed that its offline cold wallets were not affected. CEO Gracy Chen said the exchange’s $464 million user protection fund is large enough to fully cover the loss. The company is now working with Mandiant and SlowMist to investigate the source of the attack and the details of the vulnerability, while preparing to announce a withdrawal resumption plan at 4:00 UTC on Sept. 26.00
Bitget2026-09-25 13:19:01Bitget CEO says signs point to North Korea in $352 million exchange hackBitget CEO Gracy Chen said the crypto exchange’s latest security breach, which resulted in roughly $352 million in losses, likely bears the hallmarks of a North Korean operation. The incident drew attention after large outflows were seen from addresses labeled as Bitget hot and cold wallets, prompting concern across the crypto community. Researcher Specter Analyst linked the attack to the Lazarus Group, and Chen later said in a livestream that the breach showed signs associated with North Korean activity. Chen also said several blockchains have frozen addresses tied to the attack and stressed that Bitget Wallet, which is separate from the exchange, was not affected. She rejected the idea that a private key had been compromised, saying the attackers breached the wallet services backend, forged transfer details, and approved their own signing flow. According to her account, Bitget’s cold wallets remained secure, while the exchange’s hot wallets and warm wallet layers were targeted. Bitget said user funds remain safe and that most of the losses would be covered by its User Protection Fund, which Chen said currently holds more than $464 million. The company is working with Mandiant and SlowMist to investigate the breach, while withdrawals remain temporarily paused.00
Bitget2026-09-25 15:03:43Bitget says it is close to tracing attack source as stolen assets estimate rises to $387.5 millionBitget Chinese-language regional head Xie Jiayin said on Sept. 25 that the exchange’s security team has accurately identified the attack path and methods used in the latest hack, and has also obtained details on how the attacker bypassed security protections. He said the company is now very close to tracing the source of the attack. According to Xie, third-party security firms Mandiant and SlowMist are still investigating the incident, and a detailed report will be released by the security team later. On-chain tracking has confirmed that about $387.5 million in assets was transferred to hacker-controlled addresses, up from an earlier estimate of $351.6 million. The revised figure includes ZEC and TRX, and Bitget said no other unauthorized asset transfers have been found so far. Xie also said the platform-level losses will be fully covered by Bitget’s user protection fund, with no losses to user assets. In addition, Bitget has formally launched a fund recovery bounty program offering a 5% reward to participants who actively help freeze or recover the attacker’s funds.00