Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Security Flaw Enables 8M Theft from Bitget Exchange

Security Flaw Enables $388M Theft from Bitget Exchange

Posted on September 28, 2026 By CWS

The cryptocurrency exchange Bitget faced a significant security breach, losing approximately $388 million due to a vulnerability in a third-party security product, the company announced on Monday. The breach occurred when an attacker exploited this flaw to gain access to high-level internal credentials, subsequently using them on September 24 to initiate unauthorized withdrawal commands within Bitget’s wallet system.

Details of the Breach

Bitget maintains most customer funds in offline cold wallets, with hot and warm wallets used for processing withdrawals. Despite the stringent approval process required for transfers, the breach affected funds in the hot and warm wallets, leaving the cold wallets untouched. Last week, Bitget disclosed that its critical backend system had been compromised, which facilitated the spoofing of transaction data and triggered unauthorized approvals.

Bitget CEO Gracy Chen elaborated on the incident during a livestream and in interviews with The Block and Cointelegraph. The flaw provided the attacker with access to an internal management system, enabling them to insert fake withdrawal commands into backend services associated with wallets, which were mistakenly processed as legitimate requests.

Investigation and Response

Initial fraudulent activity involved two small test transfers at 18:31 UTC, which went unnoticed due to remaining below Bitget’s risk-control threshold. Larger unauthorized transfers followed approximately 30 minutes later, bypassing the exchange’s risk detection measures. Chen noted that the attacker used authentic credentials to mimic routine administrative operations, effectively erasing their digital footprint.

Bitget assured that private keys were not compromised, based on their ongoing investigation. The exploited product was not named by Chen, but she described the vulnerability as a zero-day flaw, implying it was exploited before the vendor could provide a fix. The company has notified the vendor, isolated the affected systems, and taken steps to revoke and reissue internal credentials while disabling the compromised feature.

Future Measures and Ongoing Investigation

Security firms Mandiant and SlowMist are assisting Bitget with the investigation, and a formal incident report is expected soon. The exchange has since strengthened internal access controls, implemented independent withdrawal checks, and enhanced monitoring for unusual activities. Bitget plans to reassess its use of third-party security products to prevent future breaches.

Customer account balances remain unaffected, and the loss will be covered by Bitget’s Protection Fund. Bitcoin withdrawals resumed on Monday, with other assets to follow by October 2. Users have been advised that no action is needed on their part.

Suspicion still rests on the same group of hackers previously linked to North Korea, although Chen withheld their identity pending the release of the incident report. Blockchain analytics firm TRM Labs noted overlaps between the stolen funds and past North Korean-linked thefts, hinting at involvement by the group known as TraderTraitor. TRM Labs recommended that exchanges scrutinize deposits linked to the identified exploiter addresses to prevent further laundering of the stolen assets.

The Hacker News Tags:Bitget, blockchain security, cryptocurrency exchange, cryptocurrency theft, Cybercrime, Cybersecurity, incident report, security breach, third-party vulnerability, wallet security

Post navigation

Previous Post: Microsoft Uncovers New Malware for Stealthy Network Access
Next Post: Hackers Expose AI-Driven Attack System

Related Posts

The Evolution of UTA0388’s Espionage Malware The Evolution of UTA0388’s Espionage Malware The Hacker News
AmnesiaStealer Exploits macOS Browsers for Remote Control AmnesiaStealer Exploits macOS Browsers for Remote Control The Hacker News
Apple Patches Safari Vulnerability Also Exploited as Zero-Day in Google Chrome Apple Patches Safari Vulnerability Also Exploited as Zero-Day in Google Chrome The Hacker News
APT28 Deploys BEARDSHELL and COVENANT in Ukraine Espionage APT28 Deploys BEARDSHELL and COVENANT in Ukraine Espionage The Hacker News
Meta Shuts Down 150K Accounts in Global Anti-Scam Effort Meta Shuts Down 150K Accounts in Global Anti-Scam Effort The Hacker News
Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR Detection Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR Detection The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenCode Vulnerability Risks Unauthorized Code Execution
  • Apple Fixes CoreGraphics Vulnerability in Older OS
  • Hackers Expose AI-Driven Attack System
  • Security Flaw Enables $388M Theft from Bitget Exchange
  • Microsoft Uncovers New Malware for Stealthy Network Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenCode Vulnerability Risks Unauthorized Code Execution
  • Apple Fixes CoreGraphics Vulnerability in Older OS
  • Hackers Expose AI-Driven Attack System
  • Security Flaw Enables $388M Theft from Bitget Exchange
  • Microsoft Uncovers New Malware for Stealthy Network Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark