2026-09-28 CoinTelegraph

Bitget CEO Reveals $388M Hack Exploited Third-Party Security Flaw

Bitget CEO Gracy Chen has confirmed that the crypto exchange's $388 million exploit stemmed from a vulnerability in a third-party security product, not a breach of its own private keys or cold wallets. Speaking to Cointelegraph, Chen explained that the attacker obtained "high-level internal credentials" through the flaw and used them to issue fraudulent withdrawal commands. Bitget detected unauthorized transfers from several of its hot wallets on September 24 and temporarily suspended withdrawals, initially estimating the impact at approximately $352 million.

The exchange has since patched the vulnerability and implemented stricter withdrawal controls, including restricting internal access, adding independent verification for transactions, and enhancing monitoring for suspicious activity. However, Bitget has not disclosed how much of the stolen crypto has been recovered or frozen. Chen confirmed that some assets have been frozen with assistance from industry partners, but said the exchange would release a full recovery figure only after completing internal verification.

Bitget has also called on THORChain, a decentralized cross-chain swapping protocol, to refuse service to addresses linked to the attack. THORChain has stated it cannot selectively blacklist individual addresses, and Chen acknowledged those technical constraints: "We respect the technical constraints of different networks and are not asking any protocol to take actions that are not technically possible." On the question of North Korean involvement, Chen clarified that earlier suspicions were based on preliminary indicators still under assessment. Independent forensic investigations by Mandiant and SlowMist are ongoing, with further findings expected once verified.

Read Full Article at CoinTelegraph →

Related Tool

Find Your ID

Try Now →
Check My ID