Bitget links $388M wallet theft to third-party security flaw

Cryptocurrency exchange Bitget says an attacker stole about $388 million after exploiting a vulnerability in a third-party security product used by the company. The flaw allegedly gave the intruder high-level internal credentials, which were used on September 24 to send fraudulent withdrawal commands to Bitget’s wallet system.
The stolen assets came from portions of Bitget’s hot and warm wallets, which process withdrawals. The exchange says its offline cold wallets were not affected, no private keys were compromised, and customer account balances remain intact. Bitget says its Protection Fund will cover the loss.
Valid credentials and deceptive withdrawal activity
Bitget had previously said a critical backend system in its wallet infrastructure was compromised to spoof transaction data and trigger the approval process. In its latest account, the exchange said the entry point was a flaw in an unnamed third-party security product that exposed an internal management system.
From that system, the attacker inserted fraudulent withdrawal commands into wallet-related backend services. Those commands were treated as legitimate by the workflow. Bitget CEO Gracy Chen said the attackers used valid credentials, presented their actions as routine administration and removed traces of their activity.
At 18:31 UTC on September 24, the attacker made two small test transfers that remained below Bitget’s risk-control threshold and did not trigger an alert. Larger transfers began about 30 minutes later. Bitget says its wallet system executed them and the activity bypassed its risk controls.
Containment, investigation and asset monitoring
Chen described the issue as a zero-day, meaning it was exploited before the product maker had issued a fix. Bitget says it has notified the vendor, isolated affected systems, revoked and reissued internal credentials, and disabled the affected functionality while the vulnerability is addressed. The company has not said whether a vendor patch is available.
Mandiant and SlowMist are supporting Bitget’s investigation, and the exchange expects to publish a formal incident report during the week. Bitget still suspects the same group it had linked to North Korean hackers, but Chen declined to name a group before the report is released.
TRM Labs reported overlaps between the stolen funds and wallets used to launder earlier North Korean thefts. The blockchain analytics firm said the overlap pointed to TraderTraitor, while stopping short of a firm attribution. Bitget has published recipient addresses and a live tracking dashboard, asking exchanges, stablecoin issuers, bridges, custodians and other providers to monitor and report relevant activity.
Controls must account for indirect fund movement
TRM Labs advised exchanges to screen deposits not only against tagged exploiter addresses but also against funds that originated from those addresses through several intermediate wallets. The proceeds were moving through bridges and cross-chain swap services, increasing the likelihood that incoming deposits would arrive indirectly.
Bitcoin withdrawals reopened on Monday, while other assets are due to return in stages through October 2. Bitget says users need take no action. For businesses handling digital assets, the incident is a practical reminder to treat third-party security products as privileged components, test whether legitimate credentials can defeat approval controls, and monitor transaction provenance beyond direct wallet-to-wallet transfers.

