Bitget Hack Blamed on Third-Party Security Vulnerability
Bitget's recent $388 million hack was caused by a third-party security vulnerability that allowed an attacker to obtain high-level internal credentials, according to CEO Gracy Chen.
The attacker used these credentials to issue fraudulent withdrawal commands, but Bitget's private keys were not compromised and its cold wallets were unaffected.
Bitget has since addressed the security flaw by restricting internal access, adding independent verification for withdrawals, and increasing monitoring for unusual activity.
Chen also clarified that Bitget is not asking THORChain to halt its network, but rather to refuse services to addresses linked to the attack, as it tries to prevent the stolen assets from being moved.