Bitget CEO Reveals $388M Hack Resulted from Third-Party Security Vulnerability

Bitget's CEO, Gracy Chen, disclosed that the recent $388 million breach of the crypto exchange was caused by a vulnerability in a third-party security product, enabling the attacker to acquire “high-level internal credentials.” Chen emphasized that Bitget’s private keys and cold wallets were not compromised. Following the attack on September 24, the exchange implemented stricter withdrawal controls and limited internal access to enhance security.
Attack Mechanism and Bitget’s Responsive Actions
According to CEO Gracy Chen, the attacker exploited the obtained high-level internal credentials to execute fraudulent withdrawal commands. She emphasized that Bitget’s private keys were not compromised, and its cold wallets remained unaffected.
Following the incident, Bitget addressed the security flaw and reinforced withdrawal controls by restricting internal access, implementing independent verification for withdrawals, and enhancing monitoring of unusual activities.
Attack Details and Initial Loss Estimates
The attack took place on September 24, when Bitget detected unauthorized transfers from several of its hot wallets and temporarily suspended withdrawals. The exchange initially estimated that about $352 million of assets were affected.
Later statements clarified the total stolen amount reached $388 million.
Bitget has not disclosed the specifics regarding how much of the stolen crypto has been recovered or frozen. However, Chen confirmed that, with assistance from other industry participants, some assets have been frozen and that total recovery figures will be announced after verification.
Interaction with THORChain and North Korea Attribution
Bitget previously called on THORChain, a decentralized cross-chain swapping protocol, to refuse services to addresses related to the attack. Nonetheless, the exchange does not demand a network halt, respecting the protocol’s technical constraints, as THORChain cannot selectively blacklist individual addresses.
Chen addressed earlier suspicions linking North Korea to the hack, clarifying that these were based on preliminary indicators subject to ongoing assessment. Independent forensic investigations supported by Mandiant and SlowMist are in progress, and verified findings will be shared in due course.
Why it matters
This news is significant as it details a substantial $388 million hack on the Bitget crypto exchange caused by a third-party security vulnerability. It highlights the challenges faced by major companies in the crypto industry due to threats emerging from their extended ecosystem. The information about security enhancements and ongoing investigations underlines the necessity for continuous monitoring and upgrading of platform defenses. Furthermore, the cooperation with other market participants and independent experts reflects an increasing trend of collective efforts to combat cybersecurity threats.
Prepared from the source material with AI-assisted editing and checked against the supplied facts.
Open original source ↗