Bitget Reveals Third-Party Flaw Behind $388 Million Crypto Heist
Cryptocurrency exchange **Bitget** has disclosed that a vulnerability in a third-party security product was the root cause of the recent $388 million theft. Attackers exploited this flaw to gain high-level internal credentials, subsequently bypassing risk controls and initiating fraudulent withdrawals from the exchange's hot and warm wallets.

**Bitget** confirmed on Monday that the attacker responsible for the approximate $388 million cryptocurrency theft gained access through a critical vulnerability in a third-party security product utilized by the exchange.
## Exploiting the Flaw
The exploit allowed the attacker to obtain high-level internal credentials. On September 24, these credentials were then used to send fraudulent withdrawal commands to **Bitget**'s wallet system.
While most customer funds are secured in offline cold wallets, the stolen funds originated from **Bitget**'s hot and warm wallets, which are used for processing withdrawals. The cold wallets remained unaffected.
**Bitget** CEO **Gracy Chen** elaborated on the attack, explaining that the flaw provided access to an internal management system. From there, fraudulent withdrawal commands were inserted into wallet-related backend services and processed as legitimate.
## Bypassing Risk Controls
The attack unfolded with two small test transfers at 18:31 UTC on September 24. These initial transfers remained below **Bitget**'s risk-control thresholds, failing to trigger any alerts.
Approximately 30 minutes later, larger transfers commenced, which the **Bitget** wallet system executed, effectively bypassing its established risk controls.
"Along the way, they used legitimate credentials. They disguised their activity as routine administrative operations while removing traces of their actions," **Chen** stated.
**Bitget**'s investigation so far indicates that no private keys were compromised. **Chen** described the flaw as a **zero-day vulnerability**, meaning it was exploited before a fix was available from the vendor.
## Response and Recovery
In response, **Bitget** has notified the vendor, isolated affected systems, revoked and reissued internal credentials, and disabled the compromised functionality. The exchange is supported by security firms **Mandiant** and **SlowMist** in its ongoing investigation and plans to publish a formal incident report soon.
Further security enhancements include restricted internal access, independent withdrawal checks, and increased monitoring for unusual activity. **Bitget** also plans to review its processes for assessing and deploying third-party security products.
Customer account balances were not impacted, with **Bitget**'s Protection Fund covering the losses. Bitcoin withdrawals resumed on Monday, with other assets scheduled to follow in stages through October 2.
## Attribution and Fund Tracking
While **Bitget** previously pointed to suspected North Korean hackers, **Chen** reiterated suspicions of "the same group of people" but declined to name them pending the incident report.
Blockchain analytics firm **TRM Labs** noted overlaps between the stolen funds and wallets linked to previous North Korean thefts, specifically pointing to the group **TraderTraitor**. However, **TRM Labs** has not made a definitive attribution.
**Bitget** has published the main addresses that received the stolen funds and launched a live tracking dashboard. They have urged other exchanges, stablecoin issuers, and infrastructure providers to monitor these addresses and report findings through their recovery portal.
The listed addresses for the stolen funds are:
* **Ethereum and EVM networks:** `0x770b10b273fc44fe9197d6bf20f145c2e98463ee`
* **XRP:** `rwNhefsz1UQEusxhCvHip3RANinWi4CTck`
* **Zcash:** `t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG`
* **TRON:** `TBWNguTTgezw9dVorX441C6nDrZpRxYwKD`
**TRM Labs** further advised exchanges to screen incoming deposits against exploiter addresses and funds originating from them via intermediate wallets, as proceeds are likely moving through bridges and cross-chain swap services, making indirect transfers more probable.