Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Modulate Raises $25 Million to Advance Deepfake Detection

    September 29, 2026

    ESMA Sets 2027 MiCA Crypto Supervision Priorities

    September 29, 2026

    October’s Night Sky Notes: Spooky Stargazing

    September 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Modulate Raises $25 Million to Advance Deepfake Detection
    • ESMA Sets 2027 MiCA Crypto Supervision Priorities
    • October’s Night Sky Notes: Spooky Stargazing
    • More plastic, less glow? Pollution threatens deep sea’s bioluminescent life, experts warn
    • What Xi Actually Thinks of Trump
    • ‘Cornell 7’ gang rape lawsuit: What we know about the allegations so far
    • Trump doubles down on claims US will win war with Iran ‘one way or another’ as talks are in doubt – US politics live | Trump administration
    • Burnham has a battle plan, with social care the flagship. Risks lie ahead, but Labour now travels in hope | Polly Toynbee
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 29
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 29, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalSep 28, 2026Vulnerability / Cybercrime

    The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday.

    The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget’s wallet system.

    Exchanges keep most customer funds in offline cold wallets and use hot and warm wallets to process withdrawals. Transfers from those wallets must still be approved before they are signed. The stolen funds came from part of Bitget’s hot and warm wallets, and its cold wallets were not affected.

    Bitget said last week that a critical backend system in its wallet infrastructure had been compromised and used to spoof transaction data and trigger its approval process. It had not said how the attacker got in.

    Bitget CEO Gracy Chen described the attack on Monday in a livestream, in an interview with The Block, and in comments to Cointelegraph. The flaw gave the attacker access to an internal management system. From there, the attacker inserted fraudulent withdrawal commands into wallet-related backend services, where they were treated as legitimate.

    Cybersecurity

    On September 24, the attacker first made two small test transfers at 18:31 UTC. They stayed below Bitget’s risk-control threshold and raised no alert.

    The larger transfers began about 30 minutes later, and Bitget’s wallet system executed them, bypassing its risk controls.

    “Along the way, they used legitimate credentials. They disguised their activity as routine administrative operations while removing traces of their actions,” Chen said, according to a U.Today report.

    No private keys were compromised, according to Bitget, which says that finding is based on its investigation so far.

    Chen did not name the product in her reported comments on Monday. According to The Block, she described the flaw as a zero-day, the term for a vulnerability that attackers exploit before its maker has a fix.

    Bitget has notified the vendor, isolated the affected systems, revoked and reissued internal credentials, and turned off the affected functionality while the vulnerability is addressed, Crypto Briefing reported. Bitget has not said whether the vendor has released a fix.

    This account of the attack comes from Bitget. Security firms Mandiant and SlowMist are supporting its investigation, and Bitget expects to publish a formal incident report this week.

    Bitget has since restricted internal access, added independent checks on withdrawals, and increased monitoring for unusual activity. It plans to review how it assesses and deploys third-party security products.

    Customer account balances were not affected, the exchange says. Its Protection Fund, a reserve set aside for security incidents like this one, will cover the loss.

    Bitcoin withdrawals reopened on Monday, and other assets are scheduled to follow in stages through October 2. Users do not need to take any action.

    Bitget, which last week pointed to North Korean hackers, still suspects “the same group of people,” Chen told The Block. She declined to name the group until the company’s incident report is published.

    TRM Labs, a blockchain analytics firm, said last week that it found overlaps between the stolen funds and wallets used to launder earlier North Korean thefts. Those overlaps pointed to the North Korean group TraderTraitor, but TRM had not made a firm attribution.

    Cybersecurity

    Bitget has published the main addresses that received the stolen funds, along with a live tracking dashboard. It has asked exchanges, stablecoin issuers, bridges, custodians and other infrastructure providers to watch those addresses and report what they find through its recovery portal.

    The addresses Bitget listed on September 25 were:

    • Ethereum and EVM networks: 0x770b10b273fc44fe9197d6bf20f145c2e98463ee
    • XRP: rwNhefsz1UQEusxhCvHip3RANinWi4CTck
    • Zcash: t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG
    • TRON: TBWNguTTgezw9dVorX441C6nDrZpRxYwKD

    TRM Labs advised exchanges last week to screen incoming deposits against the exploiter addresses it has tagged and against funds that originated from those addresses via several intermediate wallets, rather than only direct transfers.

    The proceeds were moving through bridges and cross-chain swap services, so deposits were more likely to arrive indirectly.

    388M attacker Bitget Exploited Flaw product Security Steal thirdparty
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Modulate Raises $25 Million to Advance Deepfake Detection

    Bitget Reveals New Details of $388M Crypto Hack

    IAM for AI agents: A Practical Enterprise Framework

    Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

    Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

    Dutch police confirm arrest in ShinyHunters hacking investigation

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Modulate Raises $25 Million to Advance Deepfake Detection

    September 29, 2026

    ESMA Sets 2027 MiCA Crypto Supervision Priorities

    September 29, 2026

    October’s Night Sky Notes: Spooky Stargazing

    September 29, 2026

    More plastic, less glow? Pollution threatens deep sea’s bioluminescent life, experts warn

    September 29, 2026
    Latest Posts

    Perez Hilton death hoax spreads online after hospitalization

    August 7, 2026

    Selling Trust From Orbit

    August 7, 2026

    Ondo Finance hit by corporate control fight as founder’s mother seeks to oust CEO

    August 7, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Modulate Raises $25 Million to Advance Deepfake Detection

    September 29, 2026

    ESMA Sets 2027 MiCA Crypto Supervision Priorities

    September 29, 2026

    October’s Night Sky Notes: Spooky Stargazing

    September 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.