Bitget CEO Says $388M Hack Exploited Third-Party Security Vulnerability
Bitget's $388 million crypto hack resulted from a third-party security flaw, not a breach of the exchange's private keys. CEO Gracy Chen stated the attacker used compromised credentials to issue fraudulent withdrawals.
Intelligence analysis by Gemini 2.5 Flash Lite

A significant $388 million crypto hack at Bitget has been attributed by CEO Gracy Chen to a vulnerability in a third-party security product. This flaw allowed attackers to gain high-level internal credentials, enabling them to execute fraudulent withdrawal commands without compromising Bitget's private keys or cold wallets. The exchange has since implemented enhanced security measures.
Imagine a big digital piggy bank (Bitget) that uses a special lockbox from another company to keep its money safe. A sneaky person found a secret way to open that special lockbox, which gave them the keys to Bitget's piggy bank. They used those keys to take out a lot of money before Bitget could fix the lockbox and stop them.
Analysis
Bitget's Security Incident
The recent $388 million exploit targeting the cryptocurrency exchange Bitget has been attributed by CEO Gracy Chen to a critical vulnerability within a third-party security product. This external flaw provided the attacker with access to high-level internal credentials, which were then leveraged to initiate fraudulent withdrawal commands. Importantly, Chen clarified that Bitget's own private keys remained secure, and its cold wallets, which store the majority of assets offline, were unaffected by the breach. The exchange has since taken steps to rectify the situation, including addressing the identified security flaw and reinforcing its withdrawal controls. These measures involve restricting internal access, implementing independent verification for all withdrawals, and enhancing monitoring systems to detect unusual activities more effectively.
Third-Party Vulnerability
The reliance on third-party security solutions, while often necessary for comprehensive protection, introduces a significant attack vector. In Bitget's case, the compromise of a security product meant that an attacker could bypass the exchange's direct defenses by exploiting an external dependency. This situation underscores a broader challenge within the digital asset industry, where the security posture of an exchange is only as strong as its weakest link, which can often be an integrated third-party service. The attacker's ability to obtain 'high-level internal credentials' suggests a deep level of access was gained, enabling them to act with significant authority within the compromised system.
Investigation and Recovery Efforts
Following the detection of unauthorized transfers on September 24, Bitget temporarily suspended withdrawals and initiated an investigation. The initial estimate of $352 million was later revised to $388 million. While some stolen assets have reportedly been frozen with the assistance of other industry participants, Bitget has yet to disclose the total amount recovered or the success rate of these efforts. CEO Gracy Chen indicated that a full disclosure would be made only after all amounts are verified. The exchange also engaged with THORChain, a cross-chain asset swapping protocol, in an attempt to prevent the movement of stolen funds, though THORChain stated its inability to blacklist individual addresses due to its decentralized nature. The investigation is also assessing a potential link to North Korea, a suspicion based on preliminary indicators, with forensic support from Mandiant and SlowMist.
Key points
- Bitget experienced a $388 million crypto hack due to a third-party security vulnerability.
- The attacker gained high-level internal credentials, enabling fraudulent withdrawal commands.
- Bitget's private keys and cold wallets were not compromised.
- The exchange has enhanced security measures, including stricter withdrawal controls and monitoring.
- Investigations are ongoing, including a potential link to North Korea, with forensic support from Mandiant and SlowMist.
Bitget's swift response in addressing the security flaw and implementing stricter withdrawal controls could bolster user confidence in the long term. The successful recovery of a significant portion of the stolen assets, aided by industry collaboration, would further demonstrate the resilience of the crypto community in combating illicit activities.
The reliance on a third-party security product exposes a critical vulnerability that could be exploited again if not thoroughly remediated. The ongoing investigation into a potential North Korean link raises concerns about sophisticated state-sponsored actors targeting crypto exchanges, potentially leading to further sophisticated attacks.

