Bitget CEO Gracy Chen stated that the crypto exchange’s recent $388 million exploit originated from a vulnerability in a third-party security product, which allowed the attacker to obtain high-level internal credentials. These credentials were subsequently used to issue fraudulent withdrawal commands. Chen clarified that Bitget’s private keys remained uncompromised and its cold wallets were unaffected by the breach.

The attack occurred on Sept. 24, when Bitget detected unauthorized transfers from several hot wallets and temporarily suspended withdrawals. The exchange initially estimated approximately $352 million in assets had been affected. Since the incident, Bitget has addressed the security flaw and tightened withdrawal controls by restricting internal access, adding independent verification for withdrawals, and increasing monitoring for unusual activity. While some assets have been frozen with assistance from other industry participants, the total recovered amount remains unverified. Bitget previously requested THORChain to refuse services to addresses linked to the attack but acknowledged the protocol cannot selectively blacklist individual addresses due to its decentralized nature. Forensic investigations are ongoing with support from Mandiant and SlowMist.