0x0f75a4140f75…0f75a417
Bitget CEO Pins $388M Hot Wallet Exploit on Third-Party Vendor Flaw
Bitget CEO Gracy Chen has attributed the exchange's roughly $388 million Sept. 24 hot-wallet breach to a vulnerability in a third-party security product, telling Cointelegraph the attacker obtained internal credentials without compromising private keys or cold storage.
Outputs
Bitget estimates the Sept. 24, 2026 hot-wallet breach at roughly $388 million, up from an initial $352 million figure.
CEO Gracy Chen attributes the exploit to a flaw in a third-party security product that yielded 'high-level internal credentials.'
Bitget says private keys and cold wallets were never compromised; only hot-wallet funds moved.
Mandiant and SlowMist are conducting the independent forensic investigation; final attribution remains unverified.
Bitget has frozen some assets with industry help but will not publish a recovery total until reconciliation ends.
Crypto exchange Bitget lost roughly $388 million in a Sept. 24, 2026 hot-wallet breach that traced to a vulnerability in a third-party security product, CEO Gracy Chen told Cointelegraph on Sept. 28.
The attacker used the flaw to extract "high-level internal credentials," then issued fraudulent withdrawal commands against Bitget's hot-wallet infrastructure, Chen said. The exchange's private keys and cold-wallet reserves were never compromised, she added, narrowing the perimeter of the breach to systems outside core key custody.
Bitget's initial public estimate placed exposure at about $352 million. The figure has since been revised upward as on-chain analysis continued, with current reporting settling near $388 million.
What did Bitget say was actually compromised?
The stolen funds moved from hot wallets only. Bitget detected the unauthorized transfers on Sept. 24 and temporarily suspended withdrawals. The exchange has since patched the third-party vulnerability and tightened withdrawal operations in three steps:
- Restricted internal access to signing infrastructure
- Added independent verification for outbound transactions
- Increased real-time monitoring for anomalous activity
Chen declined to identify the third-party vendor whose product carried the flaw, citing the active investigation. She confirmed that hot-wallet reserves sit separately from the company's broader cold-storage system.
How much of the $388 million has been recovered?
Bitget has not published a recovery total. The company said portions of the stolen assets have been frozen with help from other industry participants, but Chen said Bitget will release a verified figure only after completing internal reconciliation.
A separate cryptoslate.com report dated Sept. 29 flagged that nearly 5,000 BTC linked to the haul had begun moving through swap and mixing services.
Why is Bitget engaging with THORChain?
Bitget has asked THORChain, a cross-chain swap protocol, to refuse services to addresses flagged in the attack. THORChain has stated that its decentralized architecture cannot selectively blacklist individual wallets.
"We understand that THORChain operates as a decentralized protocol and has said that it cannot selectively blacklist individual addresses," Chen said. "We respect the technical constraints of different networks and are not asking any protocol to take actions that are not technically possible."
Bitget has not requested that THORChain halt its network or alter consensus rules.
What is the status of the forensic investigation?
Chen walked back Bitget's earlier suggestion that North Korean state-sponsored operators were responsible.
"What was shared previously was based on preliminary indicators identified during the investigation," she said. Those indicators remain under review, with independent forensic work continuing at Mandiant and SlowMist.
Attribution has not been confirmed. Bitget has committed to publish further findings once Mandiant and SlowMist complete their analysis and the exchange verifies the results.
What are the operational implications?
The breach returns attention to exchange custody architecture during a quarter when derivatives platforms have processed record volume. Bitget has not disclosed a dedicated insurance or treasury backstop earmarked for this incident.
The verified recovery number and any updated attribution are scheduled to be released once the Mandiant and SlowMist investigations conclude, an exercise Chen said will anchor Bitget's next public post-mortem.
via cnews24.ru (Original)
More from Elena Vasquez
Show full bio
Staff writer covering marketplaces and e-commerce at Mempool Brief.
439 articles