Cryptocurrency exchange Bitget says an attacker stole about $388 million after exploiting a vulnerability in a third-party security product used by the exchange.
According to Bitget, the attacker used the vulnerability to obtain high-level internal credentials and later used those credentials to submit fraudulent withdrawal commands to the exchange’s wallet system.
The incident highlights the risks crypto exchanges face not only from direct attacks on their own infrastructure, but also from vulnerabilities in third-party software and security tools.
How the Bitget Attack Happened
Bitget said the attacker gained access to an internal management system through a vulnerability in a third-party security product.
From there, the attacker was able to insert fraudulent withdrawal instructions into backend services connected to Bitget’s wallet infrastructure. Those instructions were then processed as legitimate transactions by the exchange’s approval system.
On September 24, the attacker first conducted two small test transfers at around 18:31 UTC. According to Bitget, the transfers were below its risk-control threshold and did not trigger an alert.
About 30 minutes later, the attacker began making significantly larger transfers.
Bitget said its wallet system processed those transactions, allowing the attacker to move funds from portions of the exchange’s hot and warm wallets.
Cold Wallets Were Not Affected
Cryptocurrency exchanges generally keep customer assets across different types of wallets.
- Cold wallets are kept offline and are primarily used for longer-term storage.
- Warm wallets provide a balance between security and accessibility.
- Hot wallets remain connected to online systems and are commonly used to process withdrawals.
Bitget said the stolen assets came from parts of its hot and warm wallets. Its cold wallets were not affected.
The exchange also said that private keys were not compromised, based on the investigation conducted so far.
Bitget had previously said that a critical backend component of its wallet infrastructure had been compromised and used to manipulate transaction data and trigger its approval process. At the time, however, the exchange had not disclosed how the attacker initially gained access.
Attacker Used Legitimate Credentials
Bitget CEO Gracy Chen discussed the incident in a livestream and in interviews with The Block and Cointelegraph.
According to Chen, the vulnerability provided access to an internal management system. The attacker then used that access to insert fraudulent withdrawal commands into wallet-related backend services.
The attacker reportedly used legitimate credentials and attempted to make the activity appear like routine administrative operations.
“Along the way, they used legitimate credentials. They disguised their activity as routine administrative operations while removing traces of their actions,” Chen said, according to a report by U.Today.
The Block reported that Chen characterized the vulnerability as a zero-day — a security flaw that is exploited before a fix is available from the vendor.
Chen did not publicly identify the affected security product in her reported comments.
Bitget Takes Security Measures
Following the attack, Bitget said it notified the third-party vendor and isolated the affected systems.
The exchange has also:
- Revoked and reissued internal credentials.
- Disabled the affected functionality.
- Restricted internal system access.
- Added independent checks for withdrawals.
- Increased monitoring for unusual activity.
- Begun reviewing how it evaluates and deploys third-party security products.
Bitget has not publicly confirmed whether the vendor has released a permanent fix for the vulnerability.
Cybersecurity companies Mandiant and SlowMist are assisting with the investigation. Bitget said it expects to release a formal incident report.
Bitget Says Customer Balances Are Safe
Bitget said customer account balances were not affected by the incident.
The exchange’s Protection Fund, which is maintained to respond to security incidents, will cover the stolen funds, according to the company.
Bitget also began reopening cryptocurrency withdrawals. Bitcoin withdrawals reopened on Monday, while withdrawals for other assets were scheduled to resume in stages through October 2.
The exchange said users do not need to take any action.
Possible Links to North Korean Hackers
Bitget had previously pointed to suspected North Korean hackers as a possible source of the attack.
Chen told The Block that the company still suspects the same group, but said Bitget would not identify the group publicly until its formal incident report is released.
Blockchain analytics company TRM Labs said it had identified overlaps between the stolen funds and wallets previously associated with the laundering of cryptocurrency stolen in North Korean-linked attacks.
TRM Labs said those overlaps pointed toward TraderTraitor, a group that has been associated with North Korean cyber operations. However, TRM Labs had not made a definitive attribution of the Bitget attack.
Bitget Publishes Wallet Addresses
Bitget has published addresses that received the stolen cryptocurrency and launched a tracking dashboard to monitor the movement of the funds.
The exchange has asked cryptocurrency exchanges, stablecoin issuers, bridges, custodians and other infrastructure providers to monitor the addresses and report relevant activity through its recovery portal.
The addresses published by Bitget on September 25 include:
Ethereum and EVM networks:0x770b10b273fc44fe9197d6bf20f145c2e98463ee
XRP:rwNhefsz1UQEusxhCvHip3RANinWi4CTck
Zcash:t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG
TRON:TBWNguTTgezw9dVorX441C6nDrZpRxYwKD
TRM Labs has advised exchanges to screen incoming deposits against addresses associated with the exploit as well as funds that originated from those addresses through multiple intermediate wallets.
That broader screening is important because the stolen assets were reportedly moved through cross-chain bridges and swap services. As a result, funds may reach exchanges indirectly rather than through a direct transfer from a flagged wallet.
Investigation Continues
The Bitget incident illustrates how a compromise of a third-party security product can potentially provide attackers with access to sensitive internal systems, even when an exchange’s private keys remain secure.
Bitget says its investigation is ongoing, with outside cybersecurity firms assisting with the analysis. The company is expected to provide additional details in its formal incident report.
For now, Bitget says its customer balances remain intact, its Protection Fund will cover the reported loss, and additional security controls have been introduced following the attack.
