Bitget Hacked: Attacker Exploits Security Product Flaw to Steal $388 Million
A cryptocurrency exchange called Bitget has announced that an attacker exploited a vulnerability in a third-party security product to steal $388 million from its wallets.
The attack occurred on September 24, when the attacker used high-level internal credentials obtained through the vulnerability to send fraudulent withdrawal commands to Bitget's wallet system.
Bitget CEO Gracy Chen explained that the attacker disguised their activity as routine administrative operations while removing traces of their actions.
The stolen funds came from part of Bitget's hot and warm wallets, but its cold wallets were not affected. Bitget has since restricted internal access, added independent checks on withdrawals, and increased monitoring for unusual activity.