
Third-Party Security Flaw Lets Attacker Siphon $388M from Bitget
A vulnerability in an unnamed third-party security product enabled an attacker to steal approximately $388 million from Bitget by injecting fraudulent withdrawa…
A vulnerability in an unnamed third-party security product allowed an attacker to steal approximately $388 million from the cryptocurrency exchange Bitget, the company confirmed on Monday. The flaw gave the intruder high-level internal credentials that were then used to inject fraudulent withdrawal commands directly into Bitget’s wallet system, bypassing its normal risk controls. The exchange disclosed the root cause after initially stating only that a critical backend system had been compromised and used to spoof transaction data to trigger the approval process.
Bitget CEO Gracy Chen described the attack in a livestream and in interviews with The Block and Cointelegraph. She characterized the flaw as a zero-day—a vulnerability that is actively exploited before the software vendor has released a patch. This access allowed the attacker to enter an internal management system and insert fake withdrawal requests into backend services responsible for processing transactions. Because the commands were sent using legitimate credentials and disguised as routine administrative operations, the wallet infrastructure accepted them without raising an immediate alert. According to a U.Today report, Chen said the attacker “removed traces of their actions” along the way.
The theft began on September 24 at 18:31 UTC with two small test transfers that stayed below Bitget’s risk-control threshold, triggering no warning. Approximately half an hour later, the larger transfers started, and this time the exchange’s system executed them, completely bypassing its safeguards. The funds were taken from Bitget’s hot and warm wallets—internet-connected wallets used for processing day-to-day withdrawals—while its offline cold wallets, where the vast majority of customer assets are stored, were unaffected. Bitget emphasised that no private keys were compromised, according to its investigation so far.
Bitget has not publicly identified the vulnerable third-party product. It has notified the vendor, isolated the affected systems, revoked and reissued all internal credentials, and disabled the vulnerable functionality while the flaw is addressed. The exchange brought in cybersecurity firms Mandiant and SlowMist to support the forensic investigation, and a formal incident report is expected this week. It also published the main blockchain addresses that received the stolen funds across Ethereum, XRP, Zcash, and TRON networks, and launched a live tracking dashboard. The exchange has asked other platforms, stablecoin issuers, bridge operators, and custodians to monitor those addresses and report findings through its recovery portal.
Blockchain analytics firm TRM Labs had previously identified overlaps between the stolen funds and wallets used in earlier North Korean cryptocurrency thefts, pointing toward the TraderTraitor group, though TRM stopped short of a firm attribution. Bitget itself continues to suspect “the same group of people,” Chen told The Block, but is withholding a final attribution until its incident report is complete. Meanwhile, TRM Labs advised exchanges to screen incoming deposits not just for direct transfers from the exploiter addresses but also for funds that originated from those addresses through several intermediate wallets, since the proceeds were being moved through bridges and cross-chain swap services.
Customer account balances were not affected, and Bitget’s Protection Fund—a reserve set aside specifically for security incidents—will cover the entire loss. Bitcoin withdrawals resumed on Monday, and other assets are scheduled to follow in stages through October 2. Users do not need to take any action. Since the breach, Bitget has restricted internal access, added independent checks on withdrawals, and increased monitoring for unusual activity. It also plans to review how it assesses and deploys third-party security products.
This incident is a stark reminder that any organization relying on external software components—whether a cryptocurrency exchange or a website—can be compromised through a single unpatched vulnerability in a tool that is meant to provide security. Website owners and IT teams regularly depend on third-party plugins, firewalls, monitoring agents, and cloud services; if one of those is breached, the entire system can become exposed. Rigorous vendor assessment, automatic patching, and network segmentation are critical countermeasures. For businesses that prefer to leave that heavy lifting to experts, a managed hosting provider that secures its entire stack from the ground up, such as AEU Hosting with its fully managed WordPress platform and end-to-end protections, can reduce the likelihood that a hidden third-party flaw becomes the entry point for a costly breach.
Si të Mbroheni
- If you use any security software or plugins on your website, set them to update automatically so that patches are applied as soon as they are released.
- Regularly review the administrative accounts that have access to your hosting control panel or website backend, and remove any that are no longer needed.
- Enable multi-factor authentication for all admin logins to your site, your email, and your hosting account, so that a stolen password alone is not enough.
- Monitor your system logs for any unusual activity, such as logins at odd hours or large data transfers, and set up alerts for those events.
- Maintain up-to-date backups of your entire website, stored separately from your live server, so you can restore quickly if something goes wrong.
Termat e Shpjeguar
- zero-day A security flaw that attackers are actively exploiting before the software maker has released a fix.
- cold wallet An offline cryptocurrency storage that is not connected to the internet, used to keep most funds safe from online theft.
- hot wallet An internet-connected wallet used for day-to-day transactions, which is more vulnerable to hacking.
- private keys Secret codes that prove ownership of cryptocurrency and are required to authorize any transfer out of a wallet.
- risk-control threshold A predefined limit or rule that automatically triggers an alert or blocks a transaction when something unusual is detected.
- backend services The hidden software components that handle data processing, authentication, and communication between a website or app and its databases.
- spoof To fake or falsify data so that a system believes it is legitimate, such as sending a command that appears to come from a trusted source.