HomeSecurityBitget: $388 million stolen through vulnerability in vendor's security product

Bitget: $388 million stolen through vulnerability in vendor's security product

A breach of a third-party security product allegedly paved the way for the theft of approximately $388 million from cryptocurrency exchange Bitget. According to the company’s announcements so far, the attacker exploited a critical vulnerability to obtain internal credentials high-level and insert fraudulent withdrawal orders into the digital wallet management infrastructure.

Article Image: Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

The incident, which was revealed in late September, highlights the risks that arise when critical financial services rely on software and tools from external vendors. It also raises questions about the controls that protect transactions even when attackers manage to use valid corporate credentials.

How Bitget's infrastructure was breached

Bitget CEO Gracy Chendescribed how the attack unfolded on Monday in statements to media outlets including The Block and Cointelegraph.

See also: Bitget: Is North Korea behind the theft of $351.6 million?

According to her description, the attacker exploited a vulnerability in a third-party security product, gaining access to an internal management system. From there, he was able to obtain elevated credentials and send fake commands to the backend services that handle withdrawals.

The crucial element is that the commands did not necessarily appear to be obviously malicious. Instead, according to the company, legitimate credentials were used and the actions were presented as routine administrative functions. In this way, the perpetrator was allegedly able to bypass existing security controls.

Chen called the vulnerability a zero-day, meaning a security flaw for which there was no effective fix available at the time of its exploitation. However, Bitget has not publicly named the vendor or product affected.

The test transactions before the big heist

The attack occurred on September 24th and appears to have been carried out in stages. Initially, at 18:31 UTC, the attacker executed two small test transfers, which remained within the limits allowed by the exchange's security mechanisms.

These movements did not trigger any danger warnings. About half an hour later, the larger transfers, with the wallet system approving and executing the fraudulent orders.

This sequence highlights a major problem for digital asset platforms : small transactions are not always harmless. In a targeted attack, they can be used as a test of security limits, system behavior, and the effectiveness of alerts before actual exploitation.

Which wallets were affected?

Bitget clarified that the stolen funds came from hot and warm wallets, that is, wallets that are connected to processes for direct or faster access to digital assets.

In contrast, cold wallets, which keep private keys offline, were not affected according to the company. Bitget also claims that no private keys were compromised, based on the findings of the investigation so far.

The distinction is important, as exchanges typically keep a significant portion of their inventory in cold storage, limiting exposure to attacks targeting internet-connected systems.

However, the existence of cold wallets does not eliminate all risks. If an attacker gains access to internal systems that manage transaction approvals, they can exploit weaknesses in the authorization process, without having to directly compromise the private keys.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Bitget - SecNews.gr

Countermeasures and compensation for users

After discovering the breach, Bitget notified the product vendor , isolated the affected systems , revoked any internal credentials that may have been exposed, and issued new ones. It also disabled the affected functionality until the issue was resolved.

The company also announced tighter restrictions on internal access, additional independent checks on withdrawals, and enhanced monitoring of unusual activity. It also plans to review how it evaluates and integrates third-party security products.

Bitget assured that customer account balances were not affected and that the loss will be covered by the Protection Fund, the protection reserve it maintains for security incidents.

withdrawals resumed on Monday, while the gradual restoration of withdrawals for the remaining assets was scheduled to be completed by October 2. According to the company, users do not need to take any action.

See also: Bitget: Cold wallets secure after 351.6 million breach

Investigation into possible North Korean involvement

Bitget had previously hinted that hackers from North Korea. Chen said the company is still investigating the possibility of the same group being involved, but declined to name specific perpetrators until the investigation is complete.

Blockchain analytics firm TRM Labs had identified similarities between the movement of the stolen funds and wallets used in previous thefts attributed to North Korea. The findings pointed to the TraderTraitor, but did not constitute definitive proof of responsibility.

Cybersecurity firms Mandiant and SlowMist. Bitget has said it will publish a detailed report on the incident, which is expected to clarify more technical details.

Tracking stolen cryptocurrencies

As part of the recovery efforts, Bitget has made public wallet addresses linked to the theft and created a dashboard to track the funds. It has also sought the assistance of other exchanges, stablecoin issuers, custodians, and blockchain interconnection services.

The main addresses made public on September 25 are the following:

  • Ethereum and EVM compatible networks: 0x770b10b273fc44fe9197d6bf20f145c2e98463ee
  • XRP: rwNhefsz1UQEusxhCvHip3RANinWi4CTck
  • Zcash: t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG
  • TRON: TBWNguTTgezw9dVorX441C6nDrZpRxYwKD
Bitget - SecNews.gr

Recovery, however, is not a simple matter. Attackers can transfer cryptocurrencies between different blockchains via bridges and cross-chain swaps, splitting transactions into multiple intermediary wallets. As a result, funds may end up in services that have no direct connection to the original address of the theft.

See also: Google says YouTube Music issues on iPhone have been fixed

TRM Labs has recommended that exchanges monitor not only direct transfers from known suspicious addresses, but also indirect routes of funds.

The Bitget incident highlights that the security of an exchange does not solely depend on the protection of private keys. Privilege management, external vendor evaluation, independent verification of withdrawals, and early detection of unusual transactions are equally critical layers of defense. The company’s final report is expected to clarify how the weaknesses combined to allow such a large financial loss.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS