Skip to main content

Bitget CEO: $388M Hack Linked to Third-Party Security Flaw



Bitget CEO Gracy Chen says the exchange’s reported $388 million exploit was triggered by a weakness in a third-party security product, which the attacker allegedly leveraged to obtain “high-level internal credentials.” In comments to Cointelegraph, Chen said the stolen activity involved fraudulent withdrawal commands rather than a breach of Bitget’s own private keys.



Bitget says the incident began after it detected unauthorized transfers from multiple hot wallets on Sept. 24, prompting it to temporarily suspend withdrawals. While the exchange initially estimated roughly $352 million was affected, Chen stressed that key security layers—Bitget’s private keys and cold wallets—were not compromised.



Key takeaways



  • Chen attributes the Bitget exploit to a vulnerability in a third-party security product, not to exposure of Bitget’s private keys.

  • According to Chen, attackers used obtained internal credentials to generate fraudulent withdrawal commands; Bitget’s cold wallets were unaffected.

  • Bitget says it has already patched the security flaw and tightened withdrawal controls, including limits on internal access and added verification.

  • After the attack, Bitget paused withdrawals and later resumed some services, but it has not disclosed recovery or frozen amounts.

  • Chen indicates Bitget is coordinating to freeze stolen funds, while technical limits mean it cannot rely on a decentralized protocol like THORChain to selectively block addresses.



What Bitget says happened during the Sept. 24 incident


Bitget’s account centers on the mechanism of the breach. Chen told Cointelegraph that the attacker acquired “high-level internal credentials” through a vulnerability in a third-party security product used by the exchange environment.



With those credentials, Chen said the attacker issued fraudulent withdrawal commands. Crucially, she maintained that Bitget’s private keys were not compromised and that its cold wallets were not affected. That distinction matters because it suggests the incident was more about abusing authorized execution pathways than about extracting or tampering with the most sensitive wallet material.



Cointelegraph reported that the attack occurred on Sept. 24, when Bitget detected unauthorized transfers originating from several hot wallets. Bitget initially estimated about $352 million in assets had been affected, later framing the broader figure as $388 million in exploit reporting.



Recovery status remains unclear


Despite Chen’s comments on progress, Bitget has not released how much of the stolen crypto has been recovered or frozen. Chen said some assets have been frozen with help from other participants in the industry, but Bitget plans to provide a full total only after verifying the amounts.



For investors and counterparties, this incomplete picture is a key uncertainty. Exchange hacks often progress through multiple phases—initial loss estimates, subsequent wallet tracing, cooperation with intermediaries, and eventual recoveries or clawbacks. Bitget’s decision to withhold a consolidated number until verification suggests it is still reconciling flows across affected wallets and counterparties.



Readers tracking the case should watch for updates that clarify the gap between “initially affected” funds and the later totals that are actually recovered or frozen.



Withdrawal controls tightened after the exploit


Bitget said it has addressed the underlying security flaw and changed how withdrawals are handled. Chen described steps that include restricting internal access, adding independent verification for withdrawals, and increasing monitoring for unusual activity.



The emphasis on process controls—rather than merely patching a software issue—highlights the practical lesson exchanges often face after credential-based incidents: even if core wallet safeguards remain intact, attackers can still exploit trust boundaries inside operational workflows. By tightening internal access and introducing additional independent checks, Bitget is attempting to reduce the chance that fraudulent instructions can be executed without detection.



Investors should also consider what “independent verification” could mean operationally. While the company’s description does not spell out the exact mechanism, the intent is clear: create redundancy so a single compromised credential path is insufficient to authorize withdrawals without further confirmation.



The THORChain dispute: no selective blacklists on a decentralized protocol


Bitget previously urged THORChain, a protocol designed for swapping assets between blockchains, to refuse services to addresses associated with the attack. Chen said Bitget is not asking THORChain to halt its network while it works to prevent stolen assets from moving.



At the same time, Chen acknowledged that THORChain has said it cannot selectively blacklist individual addresses. She told Cointelegraph that Bitget respects the technical constraints of decentralized protocols and is not seeking actions that are not feasible at the protocol level.



This exchange underscores a broader tension in cross-chain security incidents. Centralized exchanges can often coordinate blacklists or withdrawals controls using internal data and counterparties, but decentralized networks may be constrained by how they validate and route transactions. When stolen funds move across chains, the practical friction is often determined not by intent, but by what the underlying protocol can enforce.



Chen’s comments suggest Bitget’s strategy is to focus on actions it can drive—freezing assets, tightening operational controls, and coordinating through parties that can apply restrictions—rather than expecting the wider decentralized stack to behave like a centralized gatekeeper.



North Korea suspicion: still under forensic assessment


Chen also addressed Bitget’s earlier suspicion that North Korea may have been behind the attack, citing preliminary IP-related indicators. She told Cointelegraph that the earlier information was based on initial findings and that those indicators are still being assessed.



Chen said Mandiant and SlowMist are supporting the independent forensic investigation, and that the work is ongoing. She added that Bitget will share further findings only as they are verified.



For readers, this matters because attribution claims in major hacks can quickly become speculative. By framing its earlier indicators as preliminary and emphasizing independent forensic work, Bitget is signaling that it wants to avoid hard conclusions until evidence is corroborated.



What to watch next is whether Bitget will eventually provide a verified recovery and freezing total, and how quickly its post-incident control changes demonstrate measurable effectiveness—especially against credential-based withdrawal abuse—while attribution findings evolve from preliminary indicators into confirmed conclusions.



https://www.cryptobreaking.com/bitget-ceo-388m-hack-linked/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Bitget%20CEO:%20$388M%20Hack%20Linked%20to%20Third-Party%20Security%20Flaw%20

Comments

Popular posts from this blog

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...