0x6946e0dc6946…6946e0d9

ConfirmedSecurity473 vB120 sat/vB2 min decode

Bitget CEO Pins $388M September Hack on Third-Party Security Flaw

Bitget CEO Gracy Chen attributed the $388 million Sept. 24 exploit to a flaw in a third-party security product that yielded high-level internal credentials. Recovery figures remain undisclosed.

Bitget CEO says $388M hack exploited third-party security vulnerability
WitnessBitget CEO says $388M hack exploited third-party security vulnerabilityAI-generated

Outputs

  1. $388 million exploit hit Bitget on Sept. 24, revised from an initial $352 million estimate

  2. CEO Gracy Chen said the attacker exploited a third-party security product to obtain internal credentials

  3. Bitget's private keys and cold wallets were not compromised, Chen told Cointelegraph

  4. Bitget has not disclosed a verified recovery figure but said some assets have been frozen

  5. Mandiant and SlowMist are conducting the forensic investigation; a possible North Korea link remains under assessment

Bitget CEO Gracy Chen has attributed the exchange's $388 million exploit on Sept. 24 to a vulnerability in a third-party security product that allowed the attacker to obtain "high-level internal credentials" and issue fraudulent withdrawal commands.

Speaking to Cointelegraph, Chen said the exchange's private keys were not compromised and its cold wallets were unaffected. The credentials gave the attacker the ability to bypass controls at the application layer rather than the custody layer.

How did the attacker move funds?

Bitget detected unauthorized transfers from several hot wallets on Sept. 24 and suspended withdrawals the same day. The exchange first valued the affected assets at approximately $352 million before revising the estimate to $388 million as on-chain tracking confirmed additional outflows.

The attacker subsequently swapped ether through THORChain, a decentralized cross-chain liquidity protocol, according to prior reporting.

What is Bitget doing about the stolen funds?

Chen said the exchange has frozen some assets with help from unnamed industry participants but declined to release a total until verification is complete.

Bitget had publicly asked THORChain to refuse service to addresses linked to the exploit. THORChain responded that it cannot selectively blacklist individual wallet addresses, citing the architecture of its decentralized validator network.

"We understand that THORChain operates as a decentralized protocol and has said that it cannot selectively blacklist individual addresses," Chen said. "We respect the technical constraints of different networks and are not asking any protocol to take actions that are not technically possible."

Bitget is not asking THORChain to halt its network, the CEO added.

What operational changes has Bitget announced?

The exchange has closed the security flaw and tightened its withdrawal controls. The new measures include:

  • Restricted internal access to sensitive withdrawal functions
  • Independent verification for high-value withdrawals
  • Enhanced monitoring for unusual transactional activity

Bitget resumed Bitcoin withdrawals shortly after the incident.

Who is investigating, and is a state actor involved?

Bitget previously suggested a possible North Korean link based on early indicators. Chen walked back that framing in her latest comments.

"What was shared previously was based on preliminary indicators identified during the investigation," Chen said.

"Those indicators are still being assessed. Mandiant and SlowMist are supporting the independent forensic investigation, and that work is ongoing. We will share further findings as they are verified," she added.

Google-owned incident response firm Mandiant and blockchain forensics firm SlowMist are conducting the parallel review. Bitget has not published a target date for the report.

What happens next?

Bitget faces mounting pressure to disclose a verified recovery figure and to identify the third-party vendor whose product failed. A formal attribution to a North Korean state-linked group would mark one of the largest documented exchange exploits tied to Pyongyang and would likely reshape how centralized venues document and disclose vendor risk in post-mortem reports.

via Cointelegraph (Source)

More from Marcus Bennett

Marcus Bennett

Show full bio

Senior reporter covering business strategy at Mempool Brief.

413 articles