Bitget Reveals New Details of a $388 Million Cryptocurrency Theft Incident
Cointelegraph
1h ago
Ai Focus
The CEO of Bitget, Gracy Chen, stated that the recent $388 million theft from the exchange was due to a vulnerability in a third-party security product. The attackers took advantage of this to obtain "high-privilege internal credentials" and issued false withdrawal instructions. She mentioned that the Bitget private key was not compromised, and the cold wallets were not affected; some of the stolen assets have been frozen with the assistance of the industry, but the exchange has not yet disclosed the specific amount that has been recovered or frozen. At the same time, they are still assessing whether the incident is related to North Korea.
Helpful
No.Help

According to Bitget CEO, a $388 million hacker attack exploited a third-party security vulnerability.

Some of the stolen assets have been frozen, but as investigators continue to assess whether they may be related to North Korea, Bitget has yet to disclose how much assets have been recovered.

Bitget CEO Gracy Chen stated that the recent security incident involving $388 million at this cryptocurrency exchange stemmed from a vulnerability in a third-party security product, which allowed attackers to obtain "high-privilege internal credentials."

In an interview with Cointelegraph, Chen stated that attackers used these credentials to issue fraudulent withdrawal instructions. She said that the private key of Bitget was not leaked, and the cold wallet was not affected either.

Bitget indicates that this security vulnerability has since been fixed, and withdrawal control measures have been strengthened, including restricting internal access rights, adding independent verification for withdrawals, and enhancing monitoring of abnormal activities.

The attack occurred on September 24th. At that time, Bitget discovered unauthorized transfers from multiple of its hot wallets and temporarily suspended withdrawals. The exchange initially estimated that about $352 million in assets were affected.

Bitget has not yet disclosed the recovered data.

The exchange has not yet disclosed how much of the stolen crypto assets have been recovered or frozen. Chen indicates that with the help of participants from other industries, some of the assets have been frozen, but Bitget the total amount will only be announced after the amount is verified.

Bitget previously called on THORChain – a protocol used for exchanging assets between different blockchains – to refuse to provide services to addresses related to this attack.

The exchange stated that in attempting to prevent the transfer of stolen assets, it did not request that THORChain stop its network operations. THORChain, on the other hand, indicated that it is not possible to selectively blacklist individual addresses.

Chen indicates: "We understand that THORChain operates as a decentralized protocol, and it has been stated that it is not possible to selectively block individual addresses. We respect the technical limitations of different networks and do not require any protocol to take actions that are technically unfeasible."

Chen also mentioned the earlier suspicion that Bitget might be behind this attack on North Korea.

Chen indicates that: 'The information shared previously is based on preliminary indications identified during the investigation process.'

She added, "These signs are still being evaluated at present. Mandiant and SlowMist are supporting independent forensic investigations, and the related work is still in progress. As the results are verified, we will share further findings."

Helen Partz also provides supplementary reports on this article.

Tip
$0
Like
0
Save
0
Views 11
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
The Wi – Fi 7 EG700 gateway of Ubee Interactive has obtained comprehensive certification from Plume / OpenSync.
Ubee Interactive announces that its EG700 Wi – Fi 7-band Ethernet gateway has received comprehensive OpenSync certification from Plume Design's service suites HomePass, WorkPass, and Uprise. This gateway runs on OpenSync 6.6, supports deployment as a gateway or extender driven by Plume, and is now available for evaluation by service providers.
PR Newswire
·2026-09-29 00:44:13
2
What is the tokenization of real-world assets? A detailed explanation of bonds, stocks, and funds
The tokenization of real-world assets ( RWA tokenization ) refers to the representation of ownership or economic rights of traditional assets through blockchain-based tokens. The article introduces its basic definition, the differences under various legal and structural arrangements, and why assets such as bonds and funds are suitable for tokenization. It also points out that tokenization changes the way ownership records and transfers are managed, but does not necessarily alter the legal attributes of the assets themselves.
Coinpaper
·2026-09-29 00:35:15
5
NVIDIA Announces a Record $150 Billion in Stock Repurchases
NVIDIA's Board of Directors Approves an Additional $150 Billion in Share Repurchase Authorization, Raising the Total Authorization to $235 Billion. Jensen Huang stated that the company benefits from the wave of artificial intelligence and accelerated computing, and the strong cash flow is used not only to support investments in cutting-edge technologies but also to reward shareholders.
The Block
·2026-09-29 00:24:51
9
Datalink Networks Reports 58.2% Revenue Growth in Fiscal Year 2026
Datalink Networks announces that its revenue for the fiscal year ending August 31, 2026, was $30.1 million, a 58.2% increase from the previous year. The company stated that over 70% of its revenue came from recurring sources and plans to continue expanding its MSP and MSSP businesses, while also increasing investment in AI, cloud, and cybersecurity capabilities.
PR Newswire
·2026-09-29 00:14:07
13
Former Disney CEO Bob Chapek claimed to express concerns to the board of directors weekly during the power struggle with Iger
Former Disney executive CEO Bob Chapek stated that during his brief tenure at the media giant, he expressed his concerns to the company's board of directors "weekly" regarding the then-executive chairman Bob Iger. In his new memoirs and in interviews with CNBC, Chapek revisits this power struggle and claims that he believes Iger was "actively opposing me" at that time.
CNBC
·2026-09-29 00:14:05
15
View More