Bitget CEO says $388M hack exploited third-party security vulnerability
Some stolen assets have been frozen, but Bitget has yet to disclose how much has been recovered as investigators continue to assess a possible North Korea link.
Crypto exchange Bitget announced that a recent $388 million hack was caused by a security vulnerability in a third-party product. CEO Gracy Chen stated that the attacker obtained high-level internal credentials, which they used to issue fraudulent withdrawal commands. Bitget's private keys and cold wallets were not compromised. The exchange has since fixed the security flaw and strengthened its withdrawal controls, including limiting internal access, requiring independent verification for withdrawals, and enhancing monitoring for unusual activity.
The attack took place on September 24, when Bitget noticed unauthorized transfers from several hot wallets and temporarily halted withdrawals. Bitget has not disclosed the exact amount of recovered or frozen assets, only confirming that some have been frozen with assistance from other industry participants. The exchange has reached out to THORChain, a decentralized protocol for swapping assets between blockchains, requesting that it not facilitate service to addresses associated with the attack.
THORChain explained that it cannot selectively blacklist individual addresses. Investigations into the hack, which suggest a possible link to North Korea, are ongoing with the help of Mandiant and SlowMist. Bitget will release further findings as they are verified.
Written by urgent.news from Cointelegraph's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.