0x6946e0dc6946…6946e0d9
Bitget CEO Pins $388M September Hack on Third-Party Security Flaw
Bitget CEO Gracy Chen attributed the $388 million Sept. 24 exploit to a flaw in a third-party security product that yielded high-level internal credentials. Recovery figures remain undisclosed.

Outputs
$388 million exploit hit Bitget on Sept. 24, revised from an initial $352 million estimate
CEO Gracy Chen said the attacker exploited a third-party security product to obtain internal credentials
Bitget's private keys and cold wallets were not compromised, Chen told Cointelegraph
Bitget has not disclosed a verified recovery figure but said some assets have been frozen
Mandiant and SlowMist are conducting the forensic investigation; a possible North Korea link remains under assessment
Bitget CEO Gracy Chen has attributed the exchange's $388 million exploit on Sept. 24 to a vulnerability in a third-party security product that allowed the attacker to obtain "high-level internal credentials" and issue fraudulent withdrawal commands.
Speaking to Cointelegraph, Chen said the exchange's private keys were not compromised and its cold wallets were unaffected. The credentials gave the attacker the ability to bypass controls at the application layer rather than the custody layer.
How did the attacker move funds?
Bitget detected unauthorized transfers from several hot wallets on Sept. 24 and suspended withdrawals the same day. The exchange first valued the affected assets at approximately $352 million before revising the estimate to $388 million as on-chain tracking confirmed additional outflows.
The attacker subsequently swapped ether through THORChain, a decentralized cross-chain liquidity protocol, according to prior reporting.
What is Bitget doing about the stolen funds?
Chen said the exchange has frozen some assets with help from unnamed industry participants but declined to release a total until verification is complete.
Bitget had publicly asked THORChain to refuse service to addresses linked to the exploit. THORChain responded that it cannot selectively blacklist individual wallet addresses, citing the architecture of its decentralized validator network.
"We understand that THORChain operates as a decentralized protocol and has said that it cannot selectively blacklist individual addresses," Chen said. "We respect the technical constraints of different networks and are not asking any protocol to take actions that are not technically possible."
Bitget is not asking THORChain to halt its network, the CEO added.
What operational changes has Bitget announced?
The exchange has closed the security flaw and tightened its withdrawal controls. The new measures include:
- Restricted internal access to sensitive withdrawal functions
- Independent verification for high-value withdrawals
- Enhanced monitoring for unusual transactional activity
Bitget resumed Bitcoin withdrawals shortly after the incident.
Who is investigating, and is a state actor involved?
Bitget previously suggested a possible North Korean link based on early indicators. Chen walked back that framing in her latest comments.
"What was shared previously was based on preliminary indicators identified during the investigation," Chen said.
"Those indicators are still being assessed. Mandiant and SlowMist are supporting the independent forensic investigation, and that work is ongoing. We will share further findings as they are verified," she added.
Google-owned incident response firm Mandiant and blockchain forensics firm SlowMist are conducting the parallel review. Bitget has not published a target date for the report.
What happens next?
Bitget faces mounting pressure to disclose a verified recovery figure and to identify the third-party vendor whose product failed. A formal attribution to a North Korean state-linked group would mark one of the largest documented exchange exploits tied to Pyongyang and would likely reshape how centralized venues document and disclose vendor risk in post-mortem reports.
via Cointelegraph (Source)