Bitget CEO Gracy Chen stated that the crypto exchange’s recent $388 million exploit originated from a vulnerability in a third-party security product, which allowed the attacker to obtain high-level internal credentials. These credentials were subsequently used to issue fraudulent withdrawal commands. Chen clarified that Bitget’s private keys remained uncompromised and its cold wallets were unaffected by the breach.
The attack occurred on Sept. 24, when Bitget detected unauthorized transfers from several hot wallets and temporarily suspended withdrawals. The exchange initially estimated approximately $352 million in assets had been affected. Since the incident, Bitget has addressed the security flaw and tightened withdrawal controls by restricting internal access, adding independent verification for withdrawals, and increasing monitoring for unusual activity. While some assets have been frozen with assistance from other industry participants, the total recovered amount remains unverified. Bitget previously requested THORChain to refuse services to addresses linked to the attack but acknowledged the protocol cannot selectively blacklist individual addresses due to its decentralized nature. Forensic investigations are ongoing with support from Mandiant and SlowMist.
The attribution of the $388 million loss to a third-party security product rather than direct infrastructure failure highlights a critical dependency risk within centralized exchanges. By relying on external tools for internal credential management, Bitget exposed itself to supply chain vulnerabilities that bypassed its own perimeter defenses. This distinction is significant because it shifts the narrative from a failure of core custody protocols to a lapse in vendor integration and access control governance, suggesting that even robust cold storage architectures can be undermined by compromised intermediate software layers.
From an operational risk perspective, the inability to recover specific asset amounts and the technical constraints faced when engaging with decentralized protocols like THORChain illustrate the limitations of post-exploit containment strategies. The reliance on external forensic firms such as Mandiant and SlowMist indicates a need for independent validation of preliminary indicators, including those regarding potential state-sponsored actors. Market participants should monitor how exchanges adjust their vendor risk assessments and whether regulatory frameworks begin to mandate stricter auditing of third-party security integrations to prevent similar credential-based exploits.


