BlocktoBlockto
Bitget CEO Says $388M Hack Came From a Third Party Security Flaw
UNCATEGORIZED

Photo: Illustrative

Bitget CEO Says $388M Hack Came From a Third Party Security Flaw

Bitget's chief executive says the recent $388 million exploit started with a weakness in an outside security product, which handed the attacker high level internal credentials.

Tristan R.
By Tristan R.

Senior Author · September 28, 2026

2 min
Key takeaways
Bitget's chief executive says the recent $388 million exploit started with a weakness in an outside security product, which handed the attacker high level internal credentials.
How the Bitget Exploit Happened Gracy Chen said the attacker used those credentials to send fraudulent withdrawal commands.
She said Bitget's private keys were not compromised and its cold wallets were not touched.

Bitget’s chief executive says the recent $388 million exploit started with a weakness in an outside security product, which handed the attacker high level internal credentials.

How the Bitget Exploit Happened

Gracy Chen said the attacker used those credentials to send fraudulent withdrawal commands. She said Bitget’s private keys were not compromised and its cold wallets were not touched. The attack took place on Sept. 24, when the exchange spotted unauthorized transfers from several hot wallets and paused withdrawals. It first estimated the affected amount at about $352 million.

Security Fixes After the Bitget Breach

Bitget said it has patched the flaw and tightened withdrawal controls. Changes include restricting internal access, adding independent verification for withdrawals and increasing monitoring for unusual activity.

Stolen Crypto Recovery and THORChain

Some stolen assets have been frozen with help from other industry players, Chen said, but Bitget will publish a total only after verifying the numbers. The exchange had urged THORChain, a cross-chain swap protocol, to refuse services to addresses tied to the attack. Chen said Bitget is not asking any protocol to do something technically impossible, and THORChain has said it cannot blacklist individual addresses.

North Korea Link Still Unconfirmed

Chen said Bitget’s earlier suspicion of North Korea was based on preliminary indicators that are still being assessed. Mandiant and SlowMist are supporting an independent forensic investigation, and further findings will be shared once verified.

How markets are positioning

Live market reaction

🛢️WTI Crude
+3.4% ▲
★Gold
+1.8% ▲
₿Bitcoin
-1.8% ▼
$DXY
+0.6% ▲

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

Exclusive partner offer

Start trading
with BloFin today

Up to $500 sign-up bonus and zero-fee trading on your first 30 days.

Buy crypto now

ⓘ You will be redirected to BloFin

Share article

About the author

Tristan R.
Tristan R.

8+ years covering crypto markets, macro, and geopolitics. Previously at Decrypt and CoinDesk. Focused on the intersection of digital assets and traditional finance.