VYPR
breachPublished Sep 28, 2026· 1 source

Bitget Loses $388M After Third-Party Security Product Vulnerability Exploited

Cryptocurrency exchange Bitget reported a $388 million theft due to a vulnerability in a third-party security product, which allowed attackers to steal high-level internal credentials.

The cryptocurrency exchange Bitget has revealed that a massive $388 million theft, which occurred on September 24, was facilitated by a vulnerability in a third-party security product it utilized. The attackers exploited this flaw to gain access to high-level internal credentials, which they then used to issue fraudulent withdrawal commands to Bitget's wallet system.

According to Bitget's CEO Gracy Chen, the exploit targeted a critical backend system within the exchange's wallet infrastructure. This system was compromised, allowing the attacker to spoof transaction data and bypass the necessary approval processes for withdrawals. The stolen funds were drawn from a portion of Bitget's hot and warm wallets, while its more secure cold wallets remained unaffected.

The attack began with two small test transfers on September 24 at 18:31 UTC, which were designed to stay below Bitget's risk-control thresholds and avoid triggering any alerts. Approximately 30 minutes later, larger transfers commenced, and the compromised system executed them, circumventing the exchange's security measures. Chen stated that the attacker disguised their actions as routine administrative operations while meticulously removing traces of their activity.

Bitget has confirmed that no private keys were compromised during the incident, based on their ongoing investigation. The vulnerability is described as a zero-day, meaning it was exploited before the vendor was aware of it or had a chance to develop a fix. The exchange has since notified the vendor, isolated the affected systems, revoked and reissued internal credentials, and disabled the compromised functionality.

Security firms Mandiant and SlowMist are assisting Bitget with its investigation, and a formal incident report is expected to be published soon. In response to the breach, Bitget has implemented stricter internal access controls, added independent checks for withdrawals, and enhanced monitoring for unusual activity. The exchange also plans to reassess its procedures for evaluating and deploying third-party security products.

Customer account balances were not impacted by the theft, as Bitget's Protection Fund, a reserve established for such security incidents, will cover the losses. Bitcoin withdrawals resumed on Monday, with other assets expected to follow in stages through October 2. Users are not required to take any action.

While Bitget initially pointed to North Korean hackers, CEO Gracy Chen indicated that they still suspect the same group of actors, though she declined to name them pending the official report. Blockchain analytics firm TRM Labs noted overlaps between the stolen funds and wallets previously associated with North Korean thefts, specifically pointing to the TraderTraitor group, though a definitive attribution had not been made.

Bitget has publicly shared the main cryptocurrency addresses that received the stolen funds and launched a live tracking dashboard. They have urged exchanges and other infrastructure providers to monitor these addresses and report any findings through their recovery portal. TRM Labs has advised exchanges to screen incoming deposits against these exploiter addresses, including funds that may have passed through intermediate wallets, given the use of bridges and cross-chain swap services in the fund movement.

Synthesized by Vypr AI