Urgent.News

What's breaking now, across thousands of outlets.

Tech

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

Crypto exchange Bitget announced that a recent $388 million hack was caused by a security vulnerability in a third-party product. CEO Gracy Chen stated that the attacker obtained high-level internal credentials, which they used to issue fraudulent withdrawal commands. Bitget's private keys and cold wallets were not compromised. The exchange has since fixed the security flaw and strengthened its withdrawal controls, including limiting internal access, requiring independent verification for withdrawals, and enhancing monitoring for unusual activity.

The attack took place on September 24, when Bitget noticed unauthorized transfers from several hot wallets and temporarily halted withdrawals. Bitget has not disclosed the exact amount of recovered or frozen assets, only confirming that some have been frozen with assistance from other industry participants. The exchange has reached out to THORChain, a decentralized protocol for swapping assets between blockchains, requesting that it not facilitate service to addresses associated with the attack.

THORChain explained that it cannot selectively blacklist individual addresses. Investigations into the hack, which suggest a possible link to North Korea, are ongoing with the help of Mandiant and SlowMist. Bitget will release further findings as they are verified.

Written by urgent.news from Cointelegraph's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at thehackernews.com →

More in Tech

More from Monday 28 September →