Bitget CEO: $388M hack exploited third-party security flaw
IN SHORTCrypto exchange Bitget's $388 million hack on September 24 resulted from a vulnerability in a third-party security product, according to CEO Gracy Chen. The attacker used compromised credentials to issue fraudulent withdrawal commands, but the exchange's private keys and cold wallets were not affected. Some stolen assets have been frozen, but recovery figures remain undisclosed as investigations, including a potential North Korea link, continue.
Key Numbers
$388 millionstolen assets
$352 millioninitial estimated affected assets
Who's Involved
Bitget
crypto exchange that experienced a hack
THORChain
protocol for swapping assets between blockchains
Mandiant
supporting the independent forensic investigation
SlowMist
supporting the independent forensic investigation
↳ Why This Matters
The hack highlights ongoing security risks in the cryptocurrency industry, particularly concerning third-party integrations, and underscores the challenges in asset recovery and attribution following large-scale exploits.
Key facts
- Bitget CEO Gracy Chen stated the $388 million hack exploited a third-party security product vulnerability.
- The attacker obtained high-level internal credentials, allowing fraudulent withdrawal commands.
- Bitget's private keys and cold wallets were not compromised.
Bitget CEO Gracy Chen has stated that the cryptocurrency exchange's recent $388 million exploit was due to a vulnerability in a third-party security product. The attacker gained access to "high-level internal credentials" which were then used to issue fraudulent withdrawal commands, Chen said in comments to Cointelegraph. She clarified that Bitget's private keys were not compromised and its cold wallets remained unaffected.
The attack occurred on September 24, leading Bitget to temporarily suspend withdrawals after detecting unauthorized transfers from its hot wallets. The exchange initially estimated the affected assets at approximately $352 million. Bitget has since implemented measures to address the security flaw, including restricting internal access, adding independent verification for withdrawals, and increasing monitoring for unusual activity.
As of now, Bitget has not disclosed the total amount of stolen cryptocurrency that has been recovered or frozen. Chen indicated that some assets have been frozen with the assistance of other industry participants, but the exchange will only release a total figure after verification. Bitget had previously requested THORChain, a protocol for cross-chain asset swaps, to refuse services to addresses linked to the attack, though THORChain stated it cannot selectively blacklist individual addresses. Chen acknowledged THORChain's technical constraints and stated Bitget was not asking for technically impossible actions.
Regarding earlier suspicions of North Korea's involvement, Chen explained that preliminary indicators were still being assessed by independent forensic investigators Mandiant and SlowMist. Further findings will be shared once verified.