Bitget CEO says $388M hack exploited third-party security vulnerability
Bitget says its $388 million exploit came from a flaw in a third-party security product that let the attacker gain high-level internal credentials and submit fake withdrawal requests. Gracy Chen said private keys were not breached and cold wallets were untouched. Bitget has since fixed the vulnerability and tightened controls by limiting internal access, adding independent withdrawal verification, and improving monitoring. The attack was detected on Sept. 24, when unauthorized transfers from hot wallets triggered a withdrawal suspension. Bitget has not yet disclosed how much of the stolen crypto has been recovered or frozen, though Chen said some assets have been frozen with help from other industry participants. Bitget also clarified that it is not asking THORChain to shut down, only noting that the protocol cannot selectively blacklist addresses. Earlier claims about possible North Korea involvement were based on preliminary indicators and remain under investigation with support from Mandiant and SlowMist.
