Invest2 publishers2 min readPublished
Bitget traces its $388 million loss to a flaw in a third-party security product
Bitget says attackers may have used a flaw in a third-party security product to get internal credentials and forge $388 million of withdrawals. The account puts vendor software that can reach a withdrawal system inside an exchange's counterparty risk, alongside its own wallet controls.
The Investor · Invest desk

What happened
- Unauthorized transfers began at about 18:31 UTC on September 24 across multiple blockchains, drawing on part of Bitget's hot and warm wallet infrastructure.
- Bitget's latest reconciliation ties the transfers to 12 wallet addresses associated with its hot or warm wallets.
- Chief executive Gracy Chen hosted a live AMA on September 28 to address the incident and the phased resumption of withdrawals.
- Independent investigation reports from Mandiant and SlowMist became available on September 30.
- CertiK counted roughly $769 million lost across 99 crypto security incidents in September.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure Bitget has not named the vendor or product, so users of other exchanges cannot yet check whether the same security software sits near their platform's withdrawal system.
- contradiction Bitget says the vulnerability was remediated but also keeps the affected functionality disabled pending the vendor's fix, so the flaw is closed at Bitget by switching a feature off and may stay open wherever else the product runs.
- decision Bitget is directing its fixes at third-party deployment, internal access and withdrawal verification; key storage, which held, is not on the list.
Bitget's account of the $388 million theft starts from what held [7]. The exchange says private-key compromise has been ruled out and that its cold wallets on every chain were unaffected [9][10]. The coins left anyway. According to Bitget, the attacker appears to have used high-level internal credentials to send withdrawal commands to the wallet system, and the system executed transfers that bypassed existing risk controls [4].
The vendor comes in at the credential step. Bitget wrote that the attacker "may have exploited a vulnerability in a third-party security product to potentially obtain high-level internal credentials" [3]. The sentence carries two hedges. Cointelegraph's report drops both: in its version, the company said attackers exploited the flaw to obtain credentials and forge withdrawal commands [13]. A related Cointelegraph headline says SlowMist traced the hack activity to an Aug. 31 zero-day exploit [14]. If that date holds, 24 days passed between the exploit and the transfers [1].
If CertiK's September tally includes Bitget, as Cointelegraph's headline on third-quarter losses passing $1 billion implies [17], this one incident is about half of the month's $769 million [2]. Exploits made up $734 million of September's losses, across 58 incidents [2].
The Mandiant and SlowMist findings can cut three ways. If they confirm the vendor flaw and the product is widely deployed, the exposure extends to every exchange running it. If they show the stolen credentials alone were enough to move $388 million, the vendor supplied the entry and Bitget's own withdrawal checks allowed the loss. Bitget's description of transfers that bypassed its risk controls points partly that way [4]. The third is that the figure moves: Bitget says the $388 million estimate may be updated as tracing continues [7].
I think the first two readings are both true, or rather, the second is what makes the first expensive. A vendor bug that leaks credentials costs $388 million only when those credentials can tell the wallet system to move funds past its risk controls [7][4]. The view fails if the forensic work traces the credentials to an insider or a phished employee instead of the vendor product. Bitget says both firms are still supporting the investigation [18].
What to watch
- Whether the Mandiant and SlowMist reports confirm the third-party product as the source of the credentials, or trace them to an insider or another route.
- Whether Bitget or the vendor names the product, and whether any other exchange discloses running it.
- Revisions to the $388 million estimate as Bitget's tracing and recovery work continues.