The cryptocurrency exchange Bitget faced a significant security breach, losing approximately $388 million due to a vulnerability in a third-party security product, the company announced on Monday. The breach occurred when an attacker exploited this flaw to gain access to high-level internal credentials, subsequently using them on September 24 to initiate unauthorized withdrawal commands within Bitget’s wallet system.
Details of the Breach
Bitget maintains most customer funds in offline cold wallets, with hot and warm wallets used for processing withdrawals. Despite the stringent approval process required for transfers, the breach affected funds in the hot and warm wallets, leaving the cold wallets untouched. Last week, Bitget disclosed that its critical backend system had been compromised, which facilitated the spoofing of transaction data and triggered unauthorized approvals.
Bitget CEO Gracy Chen elaborated on the incident during a livestream and in interviews with The Block and Cointelegraph. The flaw provided the attacker with access to an internal management system, enabling them to insert fake withdrawal commands into backend services associated with wallets, which were mistakenly processed as legitimate requests.
Investigation and Response
Initial fraudulent activity involved two small test transfers at 18:31 UTC, which went unnoticed due to remaining below Bitget’s risk-control threshold. Larger unauthorized transfers followed approximately 30 minutes later, bypassing the exchange’s risk detection measures. Chen noted that the attacker used authentic credentials to mimic routine administrative operations, effectively erasing their digital footprint.
Bitget assured that private keys were not compromised, based on their ongoing investigation. The exploited product was not named by Chen, but she described the vulnerability as a zero-day flaw, implying it was exploited before the vendor could provide a fix. The company has notified the vendor, isolated the affected systems, and taken steps to revoke and reissue internal credentials while disabling the compromised feature.
Future Measures and Ongoing Investigation
Security firms Mandiant and SlowMist are assisting Bitget with the investigation, and a formal incident report is expected soon. The exchange has since strengthened internal access controls, implemented independent withdrawal checks, and enhanced monitoring for unusual activities. Bitget plans to reassess its use of third-party security products to prevent future breaches.
Customer account balances remain unaffected, and the loss will be covered by Bitget’s Protection Fund. Bitcoin withdrawals resumed on Monday, with other assets to follow by October 2. Users have been advised that no action is needed on their part.
Suspicion still rests on the same group of hackers previously linked to North Korea, although Chen withheld their identity pending the release of the incident report. Blockchain analytics firm TRM Labs noted overlaps between the stolen funds and past North Korean-linked thefts, hinting at involvement by the group known as TraderTraitor. TRM Labs recommended that exchanges scrutinize deposits linked to the identified exploiter addresses to prevent further laundering of the stolen assets.
