0x34f3a8c534f3…34f3a8c2
Bitget Traces $388M Hack to Third-Party Security Product Flaw
Bitget says attackers exploited a zero-day in a third-party security product to steal $388M from hot and warm wallets, using legitimate credentials to bypass risk controls on Sept. 24.
Outputs
Bitget lost approximately $388 million in the September 24 attack on its hot and warm wallets.
CEO Gracy Chen said the attacker exploited a zero-day flaw in an unnamed third-party security product.
Two small test transfers at 18:31 UTC preceded the larger thefts by about 30 minutes.
Cold wallets and customer balances were unaffected; Bitget's Protection Fund will cover the loss.
Bitcoin withdrawals reopened Monday; other assets resume in stages through October 2.
Crypto exchange Bitget said on Monday that the attacker who stole approximately $388 million from its wallets gained access through a vulnerability in a third-party security product the exchange used, according to CEO Gracy Chen, who detailed the incident in a livestream and interviews with The Block and Cointelegraph.
The flaw allowed the attacker to obtain high-level internal credentials. On September 24, the attacker used those credentials to send fraudulent withdrawal commands to Bitget's wallet system, which treated the commands as legitimate and executed them.
Chen did not name the affected product. According to The Block, she described the flaw as a zero-day — a vulnerability exploited before its maker has released a fix. Bitget has notified the vendor, isolated affected systems, revoked and reissued internal credentials, and disabled the affected functionality while the vulnerability is addressed, Crypto Briefing reported. The company has not confirmed whether the vendor has shipped a patch.
"Along the way, they used legitimate credentials. They disguised their activity as routine administrative operations while removing traces of their actions," Chen said, according to a U.Today report.
How did the attacker move the funds?
The attack began on September 24 at 18:31 UTC with two small test transfers that stayed below Bitget's risk-control threshold and triggered no alerts. Roughly 30 minutes later, larger transfers began, and the wallet system executed them, bypassing existing risk controls.
The stolen funds came from part of Bitget's hot and warm wallets. Cold wallets, which hold most customer funds offline, were not affected, and the exchange says no private keys were compromised, based on its investigation so far.
What comes next for Bitget operations?
Customer account balances were unaffected, and Bitget says its Protection Fund, a reserve designated for security incidents, will cover the loss. Bitcoin withdrawals reopened Monday, with other assets scheduled to resume in stages through October 2. Users need to take no action.
Mandiant and SlowMist are supporting the investigation, and Bitget expects to publish a formal incident report this week. The company has also restricted internal access, added independent checks on withdrawals, increased monitoring for unusual activity, and plans to review how it assesses and deploys third-party security products.
Who does Bitget blame?
Bitget, which pointed last week to North Korean hackers, still suspects "the same group of people," Chen told The Block, declining to name the group before the incident report is published. Blockchain analytics firm TRM Labs said it found overlaps between the stolen funds and wallets used to launder earlier North Korean thefts, pointing to the TraderTraitor cluster, though TRM stopped short of a firm attribution.
Bitget has published the main addresses that received the stolen funds, alongside a live tracking dashboard, and asked exchanges, stablecoin issuers, bridges, custodians and other infrastructure providers to monitor them and report findings through its recovery portal. The addresses listed on September 25 span four networks:
- Ethereum and EVM networks: 0x770b10b273fc44fe9197d6bf20f145c2e98463ee
- XRP: rwNhefsz1UQEusxhCvHip3RANinWi4CTck
- Zcash: t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG
- TRON: TBWNguTTgezw9dVorX441C6nDrZpRxYwKD
TRM Labs advised exchanges to screen incoming deposits not only against direct transfers from tagged exploiter addresses but also against funds originating from them through several intermediate wallets. Because the proceeds were moving through bridges and cross-chain swap services, deposits were more likely to arrive indirectly.
Bitget's formal incident report, expected this week, should clarify the vendor's patch status and the attribution question, while the staggered withdrawal reopenings through October 2 mark the operational deadline for restoring full service.
via twitter.com (Original)
More from Elena Vasquez
Show full bio
Staff writer covering marketplaces and e-commerce at Mempool Brief.
439 articles