Advertise
PRICES
InvestIn OriginalReported

Bitget says attackers used third-party flaw, not leaked keys, to move $388m

The exchange says forged withdrawal orders and stolen internal credentials drained about $388 million. Private keys and cold wallets were untouched, and its protection fund will be refilled.

Jayshree Majumdar·CEO · 4 min read

← Back to Originals

Illustration: “Bitget says attackers used third-party flaw, not”

Key updates

  • Bitget says attackers used a flaw in an outside security product to obtain internal credentials and send fake withdrawal orders.
  • CEO Gracy Chen put the amount moved at about $388 million, with private keys and cold wallets unaffected.
  • GoPlus Security said the drain lasted about 2 hours 25 minutes, with roughly $185 million moved in that window.
  • Bitget says its protection fund will be refilled to at least $300 million within a week.

Bitget says attackers did not steal private keys. Instead, they got hold of internal login credentials through a flaw in an outside security product and used them to send fake withdrawal orders, according to CoinNess and Odaily. The exchange says cold wallets, the offline storage most exchanges use for the bulk of customer funds, were not affected.

The scale is large. Bitget CEO Gracy Chen put the amount moved at about $388 million, according to PANews. Xie Jiayin, who runs Bitget's Greater China business, called it the exchange's first security incident in eight years, PANews reported. Bitget says its protection fund, a pot of money set aside to cover losses, will take the hit.

The mechanics matter more than the headline number. GoPlus Security, which reviewed the incident, said attackers breached a wallet backend, forged transaction data and made Bitget's own signing process approve transfers nobody intended, according to Wu Blockchain. That is a different problem from a stolen key. The signing flow did what it was told, because the instructions looked genuine.

What Bitget says happened

GoPlus said the drain lasted about two hours and 25 minutes, with roughly $185 million of the total moved in that window, according to Wu Blockchain. Chen said the security team traced the attack to hackers breaching a key backend system of the wallet service and using it to forge transfer information and invoke the authorised signature process, PANews reported.

Bitget has ruled out two explanations that would worry customers most. Xie said private key leaks and insider involvement are both excluded, according to Odaily. Chen said Bitget Wallet is self-custodial, meaning users hold their own keys, and runs on infrastructure separate from the exchange, its deposits, trading and rewards systems, PANews reported.

The exchange has brought in outside help. Chen said Mandiant and SlowMist are working on a full investigation, according to PANews. Xie said a third-party security team is running an independent forensic probe, with several teams checking fixes, confirming the attack path and assisting law enforcement, Odaily and PANews reported. Withdrawals will reopen once risks are cleared, he said.

The signing flow, not the keys

For crypto investors, the uncomfortable part is where the failure sat. The attack did not need to break Bitget's own cryptography. It went through a supplier, which is the same weak point that has hit other firms in the sector. If one outside product can hand over internal credentials, then every exchange that uses it is exposed until the fix is confirmed.

The market backdrop was soft as the details emerged. Bitcoin traded at $82,977, down 2.21% in 24 hours, and Ethereum at $2,659, down 1.84%, according to InvestIn.News market data at 11:05 UTC on 28 September. Total crypto market value stood at $2.84 trillion, down 4.75%, with the Crypto Fear & Greed Index at 74 of 100, in Greed territory. Nothing in the source notes ties the incident to those moves.

The two sides of this story are not really in dispute. Bitget's account and GoPlus's review agree on the broad shape: credentials, forged orders, a signing process that was tricked, no key leak. The open questions are about the third-party product, how long the exposure lasted and whether other users of that product face the same path in.

What to watch next

There is also the question of who pays and how fast. Chen said the protection fund will be refilled to at least $300 million within a week, according to Odaily. That is a promise customers can check against public wallet data. A fund that is topped up on schedule is a different signal from one that is quietly left short.

What to watch next is concrete. The Mandiant and SlowMist findings, when they land, should name the third-party product and the attack path. Withdrawal reopening will be the first live test of whether the fixes hold. And the protection fund balance, tracked on-chain, will show whether the refill promise is kept.

For now, the exchange's line is that customer assets in cold storage were never at risk and that the loss is covered. That claim rests on the investigation Bitget itself commissioned. Until those results are public, the honest position for anyone with funds on the platform is to watch the disclosures, not the assurances.

Follow the latest updates as they happen on NewsFeeds.

Sources

This article was drafted with AI assistance from the reporting listed above, then checked and edited by our writer.

We can’t find that page

The link may be old, or the address may have a typo. Search the site, or pick up from one of the desks.

Search the Site NewsFeeds NewsDesk Markets Originals PRDesk Home

No tracking hereWe set no cookies for readers and use no third-party analytics or ad trackers; we count story views ourselves, anonymously. Your theme choice, and a note that you’ve seen this message, are kept in your own browser. Read the Cookie Notice.