Advertise
PRICES
AI summary of a third-party reportNewsDesk

Bitget says $388m hack came from third-party security flaw

Bitget's chief executive says attackers used a flaw in a third-party security product to obtain internal credentials and issue fraudulent withdrawals, with some stolen assets frozen.

InvestIn.News NewsDesk · 2 min read

← Back to NewsDesk

Illustration of a crypto exchange breach, showing a padlock and digital wallet icons on a dark background.
Reported by CoinTelegraphReporter: Cointelegraph by Sam BourgiRead the original

Key points

  • Bitget CEO Gracy Chen said the $388 million exploit stemmed from a vulnerability in a third-party security product.
  • The attacker obtained high-level internal credentials and used them to issue fraudulent withdrawal commands, Chen told Cointelegraph.
  • Bitget's private keys and cold wallets were not compromised, she said.
  • The attack was detected on Sept. 24, when withdrawals were suspended; the exchange first estimated about $352 million was affected.
  • Mandiant and SlowMist are supporting the forensic investigation, and a possible North Korea link is still being assessed.

Bitget has said the $388 million hack it suffered came from a vulnerability in a third-party security product, according to comments from its chief executive. Gracy Chen told Cointelegraph that the flaw let the attacker obtain high-level internal credentials, which were then used to issue fraudulent withdrawal commands. She said Bitget's private keys were not compromised and its cold wallets were not affected.

The exchange said it has since fixed the security flaw and tightened its withdrawal controls. Those measures include restricting internal access, adding independent verification for withdrawals and increasing monitoring for unusual activity. The attack took place on Sept. 24, when Bitget detected unauthorised transfers from several hot wallets and temporarily suspended withdrawals. At the time, the exchange estimated that about $352 million in assets had been affected, a figure that has since risen to $388 million.

Third-party flaw and credentials

Bitget has not said how much of the stolen crypto has been recovered or frozen. Chen said some assets have been frozen with help from other industry participants, but the exchange will release a total only once the amounts have been verified. Bitget had earlier asked THORChain, a protocol for swapping assets between blockchains, to refuse services to addresses linked to the attack.

The exchange said it is not asking THORChain to halt its network as it tries to stop the stolen assets from being moved. THORChain has said it cannot selectively blacklist individual addresses. Chen said Bitget understands that THORChain operates as a decentralised protocol and respects the technical constraints of different networks. She added that the exchange is not asking any protocol to take actions that are not technically possible.

Withdrawals suspended after breach

Chen also addressed Bitget's earlier suspicion that North Korea may have been behind the attack. She said what was shared previously was based on preliminary indicators identified during the investigation, and that those indicators are still being assessed. Mandiant and SlowMist are supporting the independent forensic investigation, and Chen said further findings will be shared as they are verified.

The case highlights the pressure on centralised exchanges to secure the third-party tools they rely on, and the limits of asking decentralised protocols to block funds. It also shows how long recovery and attribution can take after a large exchange breach, with the final tally of frozen assets and any state link still unconfirmed.

Read the full article on CoinTelegraph →

We can’t find that page

The link may be old, or the address may have a typo. Search the site, or pick up from one of the desks.

Search the Site NewsFeeds NewsDesk Markets Originals PRDesk Home

No tracking hereWe set no cookies for readers and use no third-party analytics or ad trackers; we count story views ourselves, anonymously. Your theme choice, and a note that you’ve seen this message, are kept in your own browser. Read the Cookie Notice.