The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday.
The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system.
Exchanges keep most customer funds in offline cold wallets and use hot and warm wallets to process withdrawals. Transfers from those wallets must still be approved before they are signed. The stolen funds came from part of Bitget's hot and warm wallets, and its cold wallets were not affected.
Bitget said last week that a critical backend system in its wallet infrastructure had been compromised and used to spoof transaction data and trigger its approval process. It had not said how the attacker got in.
Bitget CEO Gracy Chen described the attack on Monday in a livestream, in an interview with The Block, and in comments to Cointelegraph. The flaw gave the attacker access to an internal management system. From there, the attacker inserted fraudulent withdrawal commands into wallet-related backend services, where they were treated as legitimate.
On September 24, the attacker first made two small test transfers at 18:31 UTC. They stayed below Bitget's risk-control threshold and raised no alert.
The larger transfers began about 30 minutes later, and Bitget's wallet system executed them, bypassing its risk controls.
"Along the way, they used legitimate credentials. They disguised their activity as routine administrative operations while removing traces of their actions," Chen said, according to a U.Today report.
No private keys were compromised, according to Bitget, which says that finding is based on its investigation so far.
Chen did not name the product in her reported comments on Monday. According to The Block, she described the flaw as a zero-day, the term for a vulnerability that attackers exploit before its maker has a fix.
Bitget has notified the vendor, isolated the affected systems, revoked and reissued internal credentials, and turned off the affected functionality while the vulnerability is addressed, Crypto Briefing reported. Bitget has not said whether the vendor has released a fix.
This account of the attack comes from Bitget. Security firms Mandiant and SlowMist are supporting its investigation, and Bitget expects to publish a formal incident report this week.
Bitget has since restricted internal access, added independent checks on withdrawals, and increased monitoring for unusual activity. It plans to review how it assesses and deploys third-party security products.
Customer account balances were not affected, the exchange says. Its Protection Fund, a reserve set aside for security incidents like this one, will cover the loss.
Bitcoin withdrawals reopened on Monday, and other assets are scheduled to follow in stages through October 2. Users do not need to take any action.
Bitget, which last week pointed to North Korean hackers, still suspects "the same group of people," Chen told The Block. She declined to name the group until the company's incident report is published.
TRM Labs, a blockchain analytics firm, said last week that it found overlaps between the stolen funds and wallets used to launder earlier North Korean thefts. Those overlaps pointed to the North Korean group TraderTraitor, but TRM had not made a firm attribution.
Bitget has published the main addresses that received the stolen funds, along with a live tracking dashboard. It has asked exchanges, stablecoin issuers, bridges, custodians and other infrastructure providers to watch those addresses and report what they find through its recovery portal.
The addresses Bitget listed on September 25 were:
- Ethereum and EVM networks: 0x770b10b273fc44fe9197d6bf20f145c2e98463ee
- XRP: rwNhefsz1UQEusxhCvHip3RANinWi4CTck
- Zcash: t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG
- TRON: TBWNguTTgezw9dVorX441C6nDrZpRxYwKD
TRM Labs advised exchanges last week to screen incoming deposits against the exploiter addresses it has tagged and against funds that originated from those addresses via several intermediate wallets, rather than only direct transfers.
The proceeds were moving through bridges and cross-chain swap services, so deposits were more likely to arrive indirectly.




