Threat Intelligence

Bitget Confirms $388M Theft Came Via Flaw in Third-Party Security Tool

The Hacker News · 29 Sept 2026
Key Takeaway Businesses relying on third-party security tools should ensure vendors patch promptly and should not assume internal risk-control thresholds alone will catch sophisticated, credential-based attacks.

Cryptocurrency exchange Bitget has confirmed that a $388 million theft from its platform was made possible by a vulnerability in a third-party security product it relied on. According to CEO Gracy Chen, attackers exploited the flaw to gain access to an internal management system, then used stolen high-level credentials to insert fraudulent withdrawal commands into the exchange's wallet backend, where they were treated as legitimate transactions.

The attack unfolded on September 24. Attackers first tested the waters with two small transfers that stayed under Bitget's risk-control threshold, avoiding detection. About 30 minutes later, larger fraudulent withdrawals followed, disguised as routine administrative activity, and Bitget's systems processed them without triggering alerts. The stolen funds came from the exchange's hot and warm wallets, which handle active transactions; its offline cold wallets, where most customer funds are stored, were not affected. Bitget says no private keys were compromised, based on its investigation to date.

Bitget has notified the affected vendor, isolated impacted systems, revoked and reissued internal credentials, and disabled the vulnerable functionality until a fix is confirmed. Security firms Mandiant and SlowMist are assisting with the investigation, and a formal incident report is expected this week.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.