Fintech & Crypto Alerts · Parker Shaw · 28 September 2026

Bitget CEO says $388M hack used third-party credentials

Bitget CEO says $388M hack used third-party credentials

Bitget CEO says 388M hack exploited a third-party security vulnerability that let an attacker obtain high-level internal credentials and issue fraudulent withdrawals. Private keys and cold wallets were not compromised, some stolen assets have been frozen, and recovery totals remain undisclosed as investigators assess a possible North Korea link.

Key Takeaways

What did Bitget say caused the $388M hack?

In comments to Cointelegraph, Bitget CEO Gracy Chen said the exchange’s recent $388 million exploit stemmed from a vulnerability in a third-party security product.

That flaw allowed the attacker to obtain “high-level internal credentials” and use them to issue fraudulent withdrawal commands. Chen said Bitget’s private keys were not compromised and its cold wallets were not affected.

The attack occurred on Sept. 24, when Bitget detected unauthorized transfers from several of its hot wallets and temporarily suspended withdrawals. The exchange initially estimated that about $352 million in assets had been affected.

How much of the stolen crypto has been recovered?

Bitget has yet to disclose how much of the stolen crypto has been recovered or frozen. Chen said some assets have been frozen with help from other industry participants, but the exchange will release a total only after verifying the amounts.

Bitget had previously called on THORChain to refuse services to addresses linked to the attack. The exchange said it is not asking THORChain to halt its network, and THORChain has said it cannot selectively blacklist individual addresses.

“We understand that THORChain operates as a decentralized protocol and has said that it cannot selectively blacklist individual addresses. We respect the technical constraints of different networks and are not asking any protocol to take actions that are not technically possible,” Chen said.

For more exchange-security coverage, see our Fintech & Crypto Alerts hub.

Is North Korea linked to the Bitget hack?

Chen also addressed Bitget’s earlier suspicion that North Korea may have been behind the attack. “What was shared previously was based on preliminary indicators identified during the investigation,” she said.

“Those indicators are still being assessed. Mandiant and SlowMist are supporting the independent forensic investigation, and that work is ongoing. We will share further findings as they are verified,” Chen added.

What security changes has Bitget made since the attack?

Bitget said it has since addressed the security flaw and tightened its withdrawal controls. Measures include restricting internal access, adding independent verification for withdrawals, and increasing monitoring for unusual activity.

The case is being tracked alongside other exchange-risk stories in our Fintech & Crypto Alerts coverage as forensic work continues.

← Open in blast feed