Skip to content

Invest2 publishers3 min readPublished

Bitget traces $387.5 million breach to stolen internal credentials via third-party product flaw

Bitget CEO Gracy Chen said the exchange's $387.5 million breach ran through a vulnerability in a third-party security product that gave attackers internal credentials to sign off fraudulent withdrawals. The loss was about 83% of its $464 million Protection Fund.

The Investor · Invest desk

Illustration accompanying Bitget traces $387.5 million breach to stolen internal credentials via third-party product flaw

What happened

  • Bitget said it has since restricted internal access, added independent verification for withdrawals and increased monitoring for unusual activity.
  • The exchange has not published a recovery figure; Chen said some assets are frozen with help from other participants but a total will come only after verification.
  • Bitcoin withdrawals resumed with 9,585 orders and 4,098.036 BTC processed by Monday afternoon, with other assets phased back through October 2.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • exposure A custody firm's attack surface now includes the security software it buys: a stolen credential from a vendor's product was enough to move funds out of hot wallets.
  • constraint Bitget can add its own withdrawal checks but cannot force THORChain to blacklist addresses, so the laundering rail stays outside its control.
  • contradiction Bitget confirms some assets are frozen but declines to quantify recovery, and the North Korea attribution it floated earlier is now described as unverified indicators.

The attack path Bitget described is the one every exchange should assume is live against its own stack. Gracy Chen said the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials, then used those credentials to issue fraudulent withdrawal commands that bypassed the exchange's risk controls [3][11]. The failure sat between the vendor's product and Bitget's own withdrawal logic. Most custody counterparties do not test that seam, because it is somebody else's code. Private keys were not compromised and the cold wallets were untouched [4].

The remediation Bitget listed is a checklist of what the controls did not do before. It restricted internal access, added independent verification for withdrawals, and increased monitoring for unusual activity [12]. Independent verification for withdrawals is the one that matters here, because a single set of stolen internal credentials was enough to sign off hot-wallet transfers without a second, out-of-band check.

The money side is more legible than the forensics. The loss started at about $352 million on detection at 18:31 UTC on September 24 [5][13], and rose to roughly $387.5 million once Bitget accounted for additional Zcash and TRON transfers, which the exchange framed as a fuller count rather than fresh theft [1][6]. The Protection Fund held more than $464 million when the incident was first disclosed [7], so the loss was about 83 percent of the fund [1]. Chen said Bitget will replenish the fund with its own capital to bring it back above $300 million within a week [8], a floor the exchange has committed to before [9]. Its August report put the fund's average monthly value at $382 million [10].

Bitget has not published a recovery number. Some assets have been frozen with help from other industry participants, but the exchange said it would release a total only after verifying the amounts [14]. On the earlier suspicion of a North Korea link, Chen said: "What was shared previously was based on preliminary indicators identified during the investigation" [15], and that "those indicators are still being assessed. Mandiant and SlowMist are supporting the independent forensic investigation, and that work is ongoing. We will share further findings as they are verified" [16].

There is a live dispute over how the stolen funds are moving. Bitget had asked THORChain, a cross-chain swap protocol, to refuse service to addresses tied to the attack; THORChain has said it cannot selectively blacklist individual addresses [17]. Chen said the exchange is not asking any protocol to do the technically impossible: "We understand that THORChain operates as a decentralized protocol and has said that it cannot selectively blacklist individual addresses. We respect the technical constraints of different networks and are not asking any protocol to take actions that are not technically possible" [18].

Bitcoin withdrawals are back. Bitget processed 9,585 orders totaling 4,098.036 BTC as of 17:00 UTC+8 on Monday, with ether, USDT and other assets phased back through October 2 [2][19]. Chen called this Bitget's first incident of this kind in eight years [20]. In my view, a custody firm's attack surface now includes the security products it buys, and the one control that would have caught this was a second verifier on the withdrawal itself.

What to watch

  • The recovery total Bitget said it will release once frozen amounts are verified, against the roughly $387.5 million lost.
  • Whether Mandiant and SlowMist confirm or drop the North Korea attribution Chen now calls preliminary.
  • Whether Bitget names the third-party vendor whose product leaked the credentials, and whether other exchanges using it respond.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories