Ethical Hacking News
Bitget, a cryptocurrency exchange, has suffered a significant security breach, resulting in the theft of approximately $388 million. The attack was made possible by an exploited vulnerability in a third-party security product used by the exchange, and is believed to have been carried out by the same group of individuals responsible for earlier North Korean thefts.
Bitget suffered a significant security breach resulting in the theft of approximately $388 million. The attack was made possible by an exploited vulnerability in a third-party security product used by the exchange. The attacker gained access to the exchange's internal management system and executed fraudulent withdrawal commands. The vulnerability was a zero-day, meaning it was not previously known to the public and had not been patched by the vendor. Bitget has taken measures to mitigate the impact, including isolating affected systems and adding independent checks on withdrawals. The stolen funds came from part of Bitget's hot and warm wallets, but the exchange's cold wallets were not affected. The attack is believed to have been carried out by the same group responsible for earlier North Korean thefts.
Bitget, a prominent cryptocurrency exchange, has recently suffered a significant security breach, resulting in the theft of approximately $388 million. The attack, which is believed to have occurred on September 24, 2026, was made possible by an exploited vulnerability in a third-party security product used by the exchange.
According to Bitget's CEO, Gracy Chen, the attacker gained access to the exchange's internal management system, which allowed them to insert fraudulent withdrawal commands into the wallet-related backend services. These commands were executed by the exchange's wallet system, bypassing its risk controls and allowing the attacker to transfer the stolen funds to various wallets.
The vulnerability exploited by the attacker was described by Chen as a zero-day, meaning that it was not previously known to the public and had not been patched by the vendor. The attack was carried out using legitimate credentials, which were used to disguise the attacker's activity as routine administrative operations.
To mitigate the impact of the attack, Bitget has taken several measures, including isolating the affected systems, revoking and reissuing internal credentials, and turning off the affected functionality. The exchange has also restricted internal access and added independent checks on withdrawals, as well as increased monitoring for unusual activity.
In addition to these measures, Bitget has published the main addresses that received the stolen funds, along with a live tracking dashboard, in an effort to track the movement of the stolen funds and to alert other exchanges, stablecoin issuers, bridges, custodians, and other infrastructure providers to watch for these addresses and report any suspicious activity through its recovery portal.
The stolen funds came from part of Bitget's hot and warm wallets, and the exchange's cold wallets were not affected. Customer account balances were not affected, and the exchange's Protection Fund, a reserve set aside for security incidents like this one, will cover the loss.
The attack is believed to have been carried out by the same group of individuals responsible for earlier North Korean thefts, as pointed out by TRM Labs, a blockchain analytics firm. TRM Labs had previously found overlaps between the stolen funds and wallets used to launder earlier North Korean thefts, which pointed to the North Korean group TraderTraitor.
The incident highlights the importance of vigilance and proactive measures in protecting against cyber threats. It also underscores the need for cybersecurity companies to continually monitor and update their security products to prevent vulnerabilities from being exploited.
In response to the attack, Bitget is planning to review how it assesses and deploys third-party security products, in an effort to prevent similar vulnerabilities from being exploited in the future.
Related Information:
https://www.ethicalhackingnews.com/articles/Exploitation-of-Third-Party-Security-Product-Flaw-Results-in-388-Million-Heist-at-Cryptocurrency-Exchange-Bitget-ehn.shtml
https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html
https://cointelegraph.com/news/bitget-388m-hack-third-party-security-vulnerability
Published: Mon Sep 28 14:23:14 2026 by llama3.2 3B Q4_K_M