Bitget Says Third-Party Security Flaw Enabled $388 Million Cryptocurrency Theft
Cryptocurrency exchange Bitget said an attacker stole approximately $388 million after exploiting a vulnerability in a third-party security product used by the exchange.
According to Bitget, the attacker used the vulnerability to obtain high-level internal credentials and later used those credentials to insert fraudulent withdrawal commands into the exchange's wallet infrastructure.
The theft occurred on September 24, 2026, and affected a portion of Bitget's hot and warm wallets. The exchange said its cold wallets were not affected.
Attacker Exploited Third-Party Security Vulnerability
Bitget said the attacker initially exploited a vulnerability in a third-party security product to gain access to an internal management system.
From there, the attacker obtained legitimate high-level credentials and used them to interact with wallet-related backend services.
The attacker allegedly inserted fraudulent withdrawal commands that were treated by the system as legitimate administrative activity.
Bitget had previously disclosed that a critical backend system in its wallet infrastructure had been compromised but had not initially explained how the attacker gained access.
The company has not publicly identified the affected third-party product.
Small Test Transfers Came Before the Main Theft
Bitget said the attacker first conducted two small test transfers at approximately 18:31 UTC on September 24.
The transactions remained below Bitget's risk-control threshold and did not trigger an alert.
Approximately 30 minutes later, the attacker began executing much larger transfers.
According to Bitget, the wallet system processed the fraudulent commands and the transactions bypassed existing risk controls.
The attacker reportedly used legitimate credentials and attempted to make the activity appear similar to normal administrative operations.
No Private Keys Were Compromised
Bitget said its investigation has found no evidence that private keys were compromised.
The stolen assets came from a portion of the exchange's hot and warm wallets, while its cold-wallet infrastructure remained unaffected.
The company also said customer account balances were not affected.
Bitget's Protection Fund, which is maintained as a reserve for security incidents, will cover the reported loss.
Bitget Responds to the Incident
Following the attack, Bitget said it:
- Isolated the affected systems
- Revoked and reissued internal credentials
- Disabled the affected functionality
- Restricted internal access
- Added independent withdrawal checks
- Increased monitoring for unusual activity
- Notified the third-party security vendor
- Began reviewing how third-party security products are assessed and deployed
Bitget has not said whether the affected vendor has released a security fix.
The company said Mandiant and SlowMist are assisting with the investigation and that a formal incident report is expected.
Cryptocurrency Withdrawals Resume
Bitget temporarily suspended withdrawals following the incident.
Bitcoin withdrawals have since resumed, while withdrawals for other assets are being restored in stages.
The exchange said customer balances remain intact and that users do not need to take action.
Suspected North Korean Connection
Bitget previously said it suspected North Korean threat actors were responsible for the theft.
The exchange continues to suspect the same group, although Bitget CEO Gracy Chen has not publicly named the group pending the company's formal incident report.
Blockchain analytics company TRM Labs previously identified overlaps between wallets involved in the Bitget theft and infrastructure associated with earlier cryptocurrency thefts attributed to North Korean actors.
TRM Labs said those overlaps pointed toward TraderTraitor, but it had not made a definitive attribution.
The attribution therefore remains an assessment rather than a confirmed identification of the attacker.
Stolen Funds Tracked Across Multiple Networks
Bitget published cryptocurrency addresses associated with the stolen funds and asked exchanges, stablecoin issuers, bridges, custodians, and other infrastructure providers to monitor them.
The addresses published by Bitget include:
Ethereum and EVM Networks
0x770b10b273fc44fe9197d6bf20f145c2e98463ee
XRP
rwNhefsz1UQEusxhCvHip3RANinWi4CTck
Zcash
t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG
TRON
TBWNguTTgezw9dVorX441C6nDrZpRxYwKD6
Bitget has also provided a live tracking dashboard and a recovery portal for organizations that identify transactions connected to the stolen assets.
Attackers Used Cross-Chain Services
TRM Labs advised cryptocurrency businesses to monitor not only direct deposits from identified exploiter addresses but also funds that originated from those addresses and moved through intermediate wallets.
The stolen cryptocurrency was reportedly moved through bridges and cross-chain swap services, making direct address-based screening less effective.
This means exchanges and other cryptocurrency infrastructure providers may need to trace transaction history across multiple intermediary addresses and blockchain networks.
Key Takeaway
The Bitget incident highlights the risks that can arise when attackers compromise a third-party security product or trusted internal system and then use legitimate credentials to manipulate financial workflows.
Although Bitget said private keys and customer balances were not compromised, the incident resulted in a major loss from hot and warm wallet infrastructure.
The investigation remains ongoing, and the final technical details, including the identity of the affected third-party product and the confirmed attribution of the attackers, are expected to provide further information about how the compromise occurred.