Bitget Reveals New Details of a $388 Million Cryptocurrency Theft Incident
Cointelegraph
1h ago
Ai Focus
The CEO of Bitget, Gracy Chen, stated that the recent $388 million theft from the exchange was due to a vulnerability in a third-party security product. The attackers took advantage of this to obtain "high-privilege internal credentials" and issued false withdrawal instructions. She mentioned that the Bitget private key was not compromised, and the cold wallets were not affected; some of the stolen assets have been frozen with the assistance of the industry, but the exchange has not yet disclosed the specific amount that has been recovered or frozen. At the same time, they are still assessing whether the incident is related to North Korea.
Helpful
No.Help

According to Bitget CEO, a $388 million hacker attack exploited a third-party security vulnerability.

Some of the stolen assets have been frozen, but as investigators continue to assess whether they may be related to North Korea, Bitget has yet to disclose how much assets have been recovered.

Bitget CEO Gracy Chen stated that the recent security incident involving $388 million at this cryptocurrency exchange stemmed from a vulnerability in a third-party security product, which allowed attackers to obtain "high-privilege internal credentials."

In an interview with Cointelegraph, Chen stated that attackers used these credentials to issue fraudulent withdrawal instructions. She said that the private key of Bitget was not leaked, and the cold wallet was not affected either.

Bitget indicates that this security vulnerability has since been fixed, and withdrawal control measures have been strengthened, including restricting internal access rights, adding independent verification for withdrawals, and enhancing monitoring of abnormal activities.

The attack occurred on September 24th. At that time, Bitget discovered unauthorized transfers from multiple of its hot wallets and temporarily suspended withdrawals. The exchange initially estimated that about $352 million in assets were affected.

Bitget has not yet disclosed the recovered data.

The exchange has not yet disclosed how much of the stolen crypto assets have been recovered or frozen. Chen indicates that with the help of participants from other industries, some of the assets have been frozen, but Bitget the total amount will only be announced after the amount is verified.

Bitget previously called on THORChain – a protocol used for exchanging assets between different blockchains – to refuse to provide services to addresses related to this attack.

The exchange stated that in attempting to prevent the transfer of stolen assets, it did not request that THORChain stop its network operations. THORChain, on the other hand, indicated that it is not possible to selectively blacklist individual addresses.

Chen indicates: "We understand that THORChain operates as a decentralized protocol, and it has been stated that it is not possible to selectively block individual addresses. We respect the technical limitations of different networks and do not require any protocol to take actions that are technically unfeasible."

Chen also mentioned the earlier suspicion that Bitget might be behind this attack on North Korea.

Chen indicates that: 'The information shared previously is based on preliminary indications identified during the investigation process.'

She added, "These signs are still being evaluated at present. Mandiant and SlowMist are supporting independent forensic investigations, and the related work is still in progress. As the results are verified, we will share further findings."

Helen Partz also provides supplementary reports on this article.

Tip
$0
Like
0
Save
0
Views 9
WalletJYS reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Datalink Networks Reports 58.2% Revenue Growth in Fiscal Year 2026
Datalink Networks announces that its revenue for the fiscal year ending August 31, 2026, was $30.1 million, a 58.2% increase from the previous year. The company stated that over 70% of its revenue came from recurring sources and plans to continue expanding its MSP and MSSP businesses, while also increasing investment in AI, cloud, and cybersecurity capabilities.
PR Newswire
·2026-09-29 00:14:07
7
Former Disney CEO Bob Chapek claimed to express concerns to the board of directors weekly during the power struggle with Iger
Former Disney executive CEO Bob Chapek stated that during his brief tenure at the media giant, he expressed his concerns to the company's board of directors "weekly" regarding the then-executive chairman Bob Iger. In his new memoirs and in interviews with CNBC, Chapek revisits this power struggle and claims that he believes Iger was "actively opposing me" at that time.
CNBC
·2026-09-29 00:14:05
8
Savus appoints Ethan Jones as Vice President of Operations Execution
Savus Announces the Appointment of Ethan Jones as Vice President of Operations, stating that He Will Be Responsible for the Company's Operational Strategy, Execution, and Expansion, and Will Serve as the Primary Operational Liaison for Platform Partners.
PR Newswire
·2026-09-29 00:02:58
9
Samsung and SK Telecom deploy private 5G smart offices for Hana Financial Group
Samsung Electronics stated that as the sole supplier, the company provided a private 5G network solution for Hana Financial Group's new headquarters located in Incheon, South Korea. The project was jointly built by Hana Financial Group, SK Telecom, and Samsung, covering 16 floors of the headquarters, multiple group subsidiaries, and thousands of employees. Samsung described this as the first of its kind in South Korea's financial industry.
The Block
·2026-09-29 00:02:57
11
Anthropic, Gamma, and Clay will discuss the situation after enterprises have truly deployed AI in Disrupt in 2026.
On TechCrunch Disrupt 2026, the responsible persons for Anthropic, Gamma, and Clay will discuss what will happen once the AI product is truly integrated into the workflow. This includes identifying which deployments are successful, which encounter delays, and how to transform the capabilities of AI into products that users will actually continue to use on a regular basis.
TechCrunch
·2026-09-28 23:55:40
14
View More