Advertise
PRICES
AI summary of a third-party reportNewsDesk

Bitget attacker tested risk controls before $388m theft, CEO says

The attacker behind Bitget's $388 million exploit made two small test transfers half an hour before draining the exchange, CEO Gracy Chen told The Block.

InvestIn.News NewsDesk · 3 min read

← Back to NewsDesk

Illustration of an exchange security breach showing wallet transfers and a shield over crypto assets
Reported by The BlockReporter: Brian DangaRead the original

Key points

  • The first unauthorised transfers came at 6:31 p.m. UTC on Sept. 24: 0.184 ETH and 193 TRX, both below Bitget's risk-control threshold.
  • Seventeen larger transactions between 6:58 p.m. and 8:09 p.m. totalled about $361 million across Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism and Avalanche.
  • Bitget's reconciliation system spotted the discrepancy at 7:05 p.m. and blocked user-initiated withdrawals platform-wide.
  • The attacker used a zero-day in a third-party security product to get admin credentials and deleted traces of fraudulent withdrawal commands.
  • The $465 million user protection fund will absorb the loss and be replenished to at least $300 million within a week from corporate reserves.

Bitget's chief executive says the attacker behind the exchange's $388 million exploit ran two small test transfers about half an hour before draining funds, according to an interview with The Block. Gracy Chen said the first unauthorised transfers took place at 6:31 p.m. UTC on Sept. 24. They included 0.184 ETH from an Ethereum hot wallet and 193 TRX from a Tron hot wallet. Both amounts sat below the exchange's risk-control threshold and triggered no system alerts, she said.

Roughly 30 minutes later, the attacker moved to larger transfers. Chen said 17 transactions across Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism and Avalanche between 6:58 p.m. and 8:09 p.m. came to about $361 million in cryptocurrency. Bitget's reconciliation system detected a significant discrepancy within seven minutes of the first large transfer, at 7:05 p.m., and its risk system blocked platform-wide user-initiated withdrawals, according to the CEO.

Chen said the attacker had already gained access to an internal management system by exploiting a zero-day vulnerability in a third-party security product. That access let them insert fraudulent withdrawal commands directly into wallet-related backend systems, so the commands were treated as legitimate. The attacker then deleted traces left by those commands, Chen said, complicating Bitget's effort to establish what happened. She described the deletion of traces as the trickiest part of the case.

Small transfers, no alerts

Bitget has said private keys and cold wallets were not compromised. The exchange is working with Mandiant and SlowMist on its investigation and expects to publish a formal incident report this week. On attribution, Chen said it was still the same group of people the exchange suspects, but declined to name them before the report is published.

The exchange's user protection fund, worth $465 million on Sept. 25, will absorb the loss. Chen said it will be replenished to at least $300 million within a week from corporate reserves, which stood at over $1.4 billion as of an Aug. 31 audit. She said an incident of this scale is very serious, but that serious does not mean existential.

Bitget has begun a phased resumption of withdrawals. BTC withdrawals resumed on Monday and processed more than 3,000 BTC in the first hour, while ETH withdrawals were set to open on Sept. 29. The exchange had previously said it would resume withdrawals in stages after the exploit.

Zero-day and deleted traces

The incident adds to a run of large exchange breaches this year and puts pressure on how platforms handle custody and third-party security tools. Bitget's decision to cover the loss from its own protection fund, rather than passing it to users, is central to its effort to keep confidence while investigators work.

Read the full article on The Block →

We can’t find that page

The link may be old, or the address may have a typo. Search the site, or pick up from one of the desks.

Search the Site NewsFeeds NewsDesk Markets Originals PRDesk Home

No tracking hereWe set no cookies for readers and use no third-party analytics or ad trackers; we count story views ourselves, anonymously. Your theme choice, and a note that you’ve seen this message, are kept in your own browser. Read the Cookie Notice.