$388M Hack on Bitget Exchanges Linked to Third-Party Security Flaw
Bitget's CEO Gracy Chen revealed that the $388 million hack on her exchange was caused by a vulnerability in a third-party security product. This allowed the attacker to obtain high-level internal credentials, which were then used to issue fraudulent withdrawal commands.
The private keys of Bitget's cold wallets were not compromised during the attack, and Chen stated that the exchange has since addressed the security flaw and tightened its withdrawal controls. These measures include restricting internal access, adding independent verification for withdrawals, and increasing monitoring for unusual activity.
Bitget initially estimated that about $352 million in assets had been affected by the hack, which occurred on September 24. The exchange temporarily suspended withdrawals after detecting unauthorized transfers from several of its hot wallets.
Chen stated that some assets have been frozen with help from other industry participants, but Bitget has not disclosed how much of the stolen crypto has been recovered or frozen yet. The exchange is working with Mandiant and SlowMist to conduct an independent forensic investigation, which is still ongoing.