Bitget CEO Gracy Chen said the crypto exchange's $388 million exploit stemmed from a vulnerability in third-party security software that enabled attackers to obtain high-level internal credentials and issue fraudulent withdrawal commands.
Chen confirmed to Cointelegraph that Bitget's private keys were not compromised and cold wallets remained unaffected. The exchange has since addressed the security flaw and implemented additional safeguards, including restricted internal access, independent verification for withdrawals, and enhanced monitoring for unusual activity.
Attack Timeline and Initial Response
The unauthorized transfers occurred on September 24, when Bitget detected suspicious activity from several hot wallets and temporarily suspended withdrawals. The exchange initially reported approximately $352 million in affected assets, later revising the figure to $388 million.
Recovery Efforts Ongoing
Bitget has not disclosed total recovery figures, though Chen stated that some stolen assets have been frozen with assistance from industry participants. The exchange plans to release comprehensive recovery totals after verifying amounts.
The exchange previously requested that THORChain, a cross-chain asset swap protocol, refuse services to addresses linked to the attack. Chen acknowledged that THORChain operates as a decentralized protocol unable to selectively blacklist individual addresses, saying Bitget respects these technical constraints.
Investigation Status
Regarding earlier speculation about North Korean involvement, Chen said preliminary indicators identified during the investigation are still being assessed. Mandiant and SlowMist are supporting an independent forensic investigation, with findings to be shared as they are verified.


