Security1 publisher2 min readPublished
Bitget traces its $388 million wallet theft to a flaw in a third-party security product
Bitget said a flaw in a third-party security product gave an attacker the internal credentials used to take about $388 million on September 24. With the product unnamed and no fix confirmed, other companies running it cannot yet check their own exposure.
The Watch · Security desk

What happened
- The stolen funds came from part of Bitget's hot and warm wallets, and its cold wallets, where exchanges keep most customer funds offline, were not affected.
- Two small test transfers at 18:31 UTC stayed below Bitget's risk-control threshold and raised no alert.
- Bitget notified the vendor, isolated the affected systems, revoked and reissued internal credentials and switched off the affected functionality, Crypto Briefing reported.
- TRM Labs found overlaps between the stolen funds and wallets that laundered earlier North Korean thefts, pointing to TraderTraitor without a firm attribution.
- Bitcoin withdrawals reopened on Monday, other assets return in stages through October 2, and users do not need to take any action.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Other companies running the unnamed product may have the same zero-day route to privileged internal credentials, and they cannot check without the product's name.
- constraint An approval process that trusts data from the backend it protects will approve whatever that backend reports. At Bitget, spoofed transaction data triggered approvals once the backend was compromised.
- decision Bitget's review of how it assesses and deploys third-party security products puts the same question to every exchange: how much internal access a defensive tool gets, and what it reaches if compromised.
- cost The loss falls on Bitget's Protection Fund, not on customer balances, so the exchange carries it in full while recovery depends on other platforms flagging funds at the published addresses.
Chen described the flaw to The Block as a zero-day [11]. It gave the attacker high-level internal credentials and access to an internal management system [2][6]. From there the attacker wrote fraudulent withdrawal commands into wallet-related backend services, and those services treated them as legitimate [6].
At Bitget, hot and warm wallet transfers must be approved before they are signed [4]. Last week the exchange said a compromised backend system had been used to spoof transaction data and trigger that approval process [5]. So the approval step was checking records the attacker had written [5][6]. Bitget says its investigation so far found no private keys compromised [10]. The attacker did not need them. Bitget's own wallet system executed the larger transfers, bypassing its risk controls [8].
"Along the way, they used legitimate credentials. They disguised their activity as routine administrative operations while removing traces of their actions," Chen said, according to a U.Today report [9]. The larger transfers began around 19:01 UTC, about half an hour after the test transfers [1].
Chen did not name the product [11]. Bitget has not said whether the vendor has released a fix [13]. Its other changes are to its own controls. It restricted internal access, added independent checks on withdrawals and increased monitoring for unusual activity [15]. It also plans to review how it assesses and deploys third-party security products [15].
Attribution is still soft. Chen told The Block the company still suspects "the same group of people" behind the theft, after pointing last week to North Korean hackers, and she declined to name the group until the incident report is out [18]. TRM's link is on-chain laundering evidence [19]. Evidence about the intrusion itself is held by Bitget. Mandiant and SlowMist are supporting its investigation, and the exchange expects to publish a formal incident report this week [14].
The proceeds were moving through bridges and cross-chain swap services [20]. TRM advised exchanges to screen deposits against the exploiter addresses it has tagged, and against funds that came from those addresses through several intermediate wallets [20]. Bitget has published the main receiving addresses and a live tracking dashboard, and it has asked exchanges, stablecoin issuers, bridges and custodians to report sightings through its recovery portal [21].
What to watch
- Bitget's formal incident report, expected this week, and whether it names the security product and the vendor's fix status.
- An advisory or patch from the unnamed vendor, or another of its customers reporting the same credential theft.
- Whether TRM Labs or Bitget moves from wallet overlaps to a firm attribution to TraderTraitor.