Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
CLAY TRIBUNE.
Advertisement

Third-party flaw behind $388M hack of Bitget, per CEO

Bitget CEO says $388M hack exploited a third-party security flaw, allowing attackers to steal high-level credentials.

By mitch·3 min read
A cracked digital lock symbolizing a cyber security breach at a cryptocurrency exchange.

Bitget CEO Gracy Chen says the $388 million hack that hit the exchange last month exploited a vulnerability in a third-party security product, allowing the attacker to grab high-level internal credentials.

On Sept. 24, Bitget spotted unauthorized transfers from several of its hot wallets and paused withdrawals temporarily. The exchange first guessed that roughly $352 million in assets had been affected. According to Chen, Bitget’s private keys were left unharmed, and its cold wallets remained untouched.

Chen’s account of the flaw

The attacker was able to issue fraudulent withdrawal instructions using the stolen credentials, Chen explained to Cointelegraph. She added that the firm has since fixed the security flaw and tightened its withdrawal controls, which now include restricting internal access, adding independent verification for withdrawals and increasing monitoring for unusual activity.

Advertisement

Chen confirmed that some stolen funds have been frozen, even if Bitget has not yet disclosed how much has been recovered. The exchange plans to release a total figure only after verifying the amounts.

The THORChain standoff

THORChain was approached by Bitget and asked to refuse services to addresses tied to the attack. The protocol is unable to selectively blacklist individual addresses.

“We understand that THORChain operates as a decentralized protocol and has said that it cannot selectively blacklist individual addresses,” Chen said. “We respect the technical constraints of different networks and are not asking any protocol to take actions that are not technically possible.”

North Korea remains unconfirmed

Chen addressed Bitget’s earlier suspicion that North Korea may have been behind the attack. “What was shared previously was based on preliminary indicators identified during the investigation,” she said.

“Those indicators are still being assessed. Mandiant and SlowMist are supporting the independent forensic investigation, and that work is ongoing. We will share further findings as they are verified,” she added.

Recovery figures remain undisclosed

No recovery numbers have been announced by Bitget. Some assets have been frozen, with assistance from other industry players, though Chen confirmed verified totals remain unreleased.

Further analysis is still underway, with Mandiant and SlowMist providing support for the forensic work. Chen stated that the exchange will release additional findings as they are confirmed.

Key facts

  • Hack: $388 million in assets affected
  • Initial estimate: about $352 million
  • Date: Sept. 24
  • Recovery: Some assets frozen, recovery total not disclosed
  • Investigation support: Mandiant and SlowMist

The recovery question

The main unknown remains straightforward: what share of funds has Bitget managed to recover? Some assets have been frozen by the company, yet no figure for the total amount has been disclosed.

The commitment to confirm totals before publication implies the number could change considerably once the counts are final. Until that point, shareholders remain uncertain about a figure that may fluctuate with each fresh recovery.

Where things stand

Bitget has tightened its withdrawal controls after addressing a security flaw, and has frozen some assets with assistance from other industry participants, though it has not disclosed how much has been recovered.

Chen has pledged to share verified findings as they arrive. The company is collaborating with Mandiant and SlowMist on the probe.

It is clear that the complete account will come together slowly, and the exchange has made plain it will not force the figures out before they are confirmed.

Source material: “Bitget CEO says $388M hack exploited third-party security vulnerability,” Cointelegraph.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.