Bitget CEO says $388M hack exploited third-party security vulnerability

Bitget CEO Gracy Chen said the exchange’s reported $388 million exploit on Sept. 24 resulted from a vulnerability in a third-party security product that allowed the attacker to obtain high-level internal credentials and execute unauthorized withdrawals. Bitget said its private keys and cold wallets were not compromised, some stolen assets have been frozen, and forensic firms are investigating possible links to North Korea.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished 1 minute agoUpdated 1 minute ago0 views
Bitget CEO says $388M hack exploited third-party security vulnerability

Why It Matters

The incident highlights supply-chain and third-party risks for centralized crypto exchanges, and shows how attackers can bypass internal controls without compromising core wallet keys. Ongoing forensic work and industry coordination will determine how much theft has been recovered and whether nation-state actors were involved.

Key Facts

  • Date of attack: Sept. 24, 2024
  • Total reported exploit amount: $388 million
  • Initial affected-assets estimate: About $352 million (initial estimate by Bitget)
  • Source of vulnerability: Third-party security product that allowed access to high-level internal credentials
  • Impact on private keys and cold wallets: Bitget says private keys were not compromised and cold wallets were not affected.

Bitget CEO Gracy Chen told Cointelegraph that the exchange’s recent $388 million security breach originated from a weakness in a third-party security product. According to Chen, the attacker used the resulting high-level internal credentials to issue fraudulent withdrawal commands from Bitget’s hot wallets, prompting the company to detect unauthorized transfers and temporarily suspend withdrawals on Sept. 24.

Bitget said its private keys and cold wallets remained secure and were not accessed during the incident. The exchange also reported an earlier estimate that roughly $352 million in assets had been affected. Chen added that some stolen funds have been frozen with assistance from other industry participants, but Bitget has not yet published a verified total for recovered or frozen assets.

In response to the exploit, Bitget said it has remediated the third-party security flaw and tightened withdrawal procedures, including restricting internal access, adding independent verification for withdrawals, and enhancing monitoring for unusual activity. The company previously asked THORChain to refuse services to addresses linked to the attack, while clarifying it was not requesting the protocol to shut down. THORChain has stated it cannot selectively blacklist individual addresses.

Bitget also addressed preliminary suggestions of a North Korea link to the incident, saying earlier indicators were tentative and remain under assessment. Independent forensic investigations are underway with support from firms including Mandiant and SlowMist; Bitget said it will disclose further findings once they have been verified.

Keep Reading