Bitget Says $388M Hack Stemmed From Third-Party Security Vulnerability
Key Takeaways
- •Bitget's $388 million exploit was traced to a vulnerability in a third-party security product that allowed the attacker to obtain high-level internal credentials rather than compromising private keys.
- •The attacker used the stolen credentials to issue fraudulent withdrawal commands, while Bitget's private keys and cold wallets remained unaffected.
- •The Sept. 24 attack targeted several internet-connected hot wallets, initially affecting an estimated $352 million in assets and prompting a temporary withdrawal suspension.
- •Bitget has addressed the flaw and tightened security with restricted internal access, independent withdrawal verification, and increased monitoring, though a verified recovery total has not been disclosed despite some assets being frozen with industry assistance.
- •Mandiant and SlowMist are conducting an ongoing independent forensic investigation, and preliminary indicators pointing to possible North Korean involvement are still being assessed.

Bitget CEO Gracy Chen said the exchange's recent $388 million exploit stemmed from a vulnerability in a third-party security product that allowed the attacker to obtain “high-level internal credentials.” The detail underscores that operational credentials, not only private keys, can be an attack vector for exchanges.
In comments to Cointelegraph, Chen said the attacker used those credentials to issue fraudulent withdrawal commands. Bitget's private keys were not compromised, and its cold wallets were not affected, she said. The distinction matters because hot wallets — internet-connected wallets exchanges use to process day-to-day withdrawals — carry more exposure than cold storage, where private keys are kept offline and the bulk of an exchange's holdings typically sits.
The attack took place on Sept. 24, when Bitget detected unauthorized transfers from several of its hot wallets and temporarily suspended withdrawals. The exchange initially estimated that about $352 million in assets had been affected.
Security controls tightened
Bitget said it has since addressed the security flaw and tightened its withdrawal controls. Measures include restricting internal access, adding independent verification for withdrawals and increasing monitoring for unusual activity. Independent verification, in particular, is meant to ensure a single set of credentials cannot trigger withdrawals on its own.
Recovery figures not yet disclosed
The exchange has not disclosed how much of the stolen crypto has been recovered or frozen. Chen said some assets have been frozen with help from other industry participants, but Bitget would release a total only after verifying the amounts, leaving the recovery figure and the forensic findings as the main open items in the case.
Bitget had previously called on THORChain, a protocol for swapping assets between blockchains, to refuse services to addresses linked to the attack. The exchange said it is not asking THORChain to halt its network as it attempts to prevent the stolen assets from being moved. THORChain has said it cannot selectively blacklist individual addresses. Decentralized protocols like THORChain process swaps through automated code rather than a central operator, which is why there is no built-in mechanism to block specific addresses.
“We understand that THORChain operates as a decentralized protocol and has said that it cannot selectively blacklist individual addresses. We respect the technical constraints of different networks and are not asking any protocol to take actions that are not technically possible,” Chen said.
North Korea involvement still under assessment
Chen also addressed Bitget's earlier suspicion that North Korea may have been behind the attack.
“What was shared previously was based on preliminary indicators identified during the investigation,” Chen said. “Those indicators are still being assessed. Mandiant and SlowMist are the independent forensic investigation, and that work is ongoing. We will share further findings as they are verified,” she added. Mandiant is a cybersecurity firm specializing in incident response, while SlowMist is a blockchain security company.
Additional reporting by Helen Partz.