Key Points:
- Bitget CEO Gracy Chen said the exchange’s $388 million exploit originated from a vulnerability in a third-party security product that exposed high-level internal credentials.
- The attacker allegedly used those credentials to issue fraudulent withdrawal commands, while Bitget said its private keys and cold wallets were not compromised.
- Some stolen assets have been frozen, but Bitget has not disclosed a verified recovery total as forensic investigators examine the incident and a possible North Korea connection.
Third-Party Vulnerability Enabled Unauthorized Withdrawals
Bitget CEO Gracy Chen said the exchange’s recent $388 million security incident was caused by a vulnerability in a third-party security product that allowed an attacker to obtain high-level internal credentials.
According to Chen, those credentials were subsequently used to issue fraudulent withdrawal commands from the exchange’s hot-wallet infrastructure.
Bitget said its private keys were not compromised and that its cold wallets remained unaffected, limiting the incident to specific operational systems and hot-wallet assets.
The exchange has since addressed the reported vulnerability and introduced additional withdrawal controls. These measures include restricting internal access, requiring independent verification for withdrawals and increasing monitoring for unusual activity.
September Attack Targeted Hot Wallets
The incident occurred on Sept. 24, when Bitget detected unauthorized transfers from several hot wallets and temporarily suspended withdrawals.
The exchange initially estimated that approximately $352 million in digital assets had been affected before subsequent assessments increased the reported value of the exploit to roughly $388 million.
The incident highlights the risks associated with centralized exchange infrastructure, where operational systems, security tools and internal authorization mechanisms can become potential attack surfaces even when core custody systems remain protected.
Recovery Figures Remain Undisclosed
Bitget has not yet published a verified figure for the amount of cryptocurrency recovered or frozen following the attack.
Chen said some assets had been frozen with assistance from other participants in the crypto industry. However, she said the exchange would release a total recovery figure only after the amounts had been independently verified.
Bitget had also contacted THORChain in an effort to prevent addresses associated with the attack from being used to swap the stolen assets across blockchains.
The exchange said it was not asking THORChain to halt its broader network or take actions that its decentralized architecture cannot support.
THORChain Cannot Selectively Blacklist Addresses
THORChain has said it cannot selectively blacklist individual addresses because of the way its decentralized protocol operates.
Bitget acknowledged those technical limitations and said it respected the constraints of different blockchain networks.
The exchange’s approach instead focuses on identifying and tracking stolen assets while working with other industry participants to freeze funds where centralized services or custodial platforms have the ability to intervene.
The ability to recover stolen crypto therefore depends partly on whether attackers move assets through services capable of freezing or blocking transactions.
North Korea Link Still Under Investigation
Chen also addressed earlier speculation that North Korean actors could have been responsible for the attack.
She said the previous assessment was based on preliminary indicators identified during the investigation rather than a confirmed attribution.
Mandiant and SlowMist are supporting the independent forensic investigation, which remains ongoing.
Bitget said additional findings will be released once they have been verified, leaving the potential North Korean connection unconfirmed at this stage.
Security Controls Tightened After Exploit
Bitget’s response includes tighter internal access restrictions, additional verification for withdrawals and enhanced monitoring designed to identify abnormal activity.
The incident illustrates how attacks against crypto exchanges can involve more than direct compromise of blockchain wallets. Internal credentials, security products and authorization systems can also become critical targets when attackers seek to initiate legitimate-looking transactions from exchange infrastructure.
Bitget’s assertion that its cold wallets and private keys were not compromised suggests the attack centered on operational controls rather than direct theft of the exchange’s core offline custody infrastructure.
Outlook
Bitget’s investigation remains focused on determining the full scope of the breach, verifying the amount of assets frozen or recovered and identifying how the third-party security vulnerability was exploited. The exchange’s updated withdrawal controls and ongoing forensic work could provide further details as investigators establish the attacker’s methods and assess the potential attribution to North Korea.
Comparison, examination, and analysis between investment houses
Leave your details, and an expert from our team will get back to you as soon as possible