The CEO of Bitget, Gracy Chen, revealed that the $388 million breach that hit the platform was not the result of a direct compromise of its core infrastructure, but instead began through a security vulnerability in a third-party product that enabled the attacker to access “high-level internal credits.”
According to what Chen explained, these permissions were used to issue fraudulent withdrawal orders, while she confirmed that the private keys were not compromised and that the cold wallets were unaffected by the incident.
Bitget indicated that it patched the vulnerability after discovering it, and tightened withdrawal controls through a set of measures, including:
• Restricting internal access.
• Adding an independent verification step for withdrawal operations.
• Increasing monitoring of unusual activity.
The platform had detected on September 24 unauthorized transfers from several hot wallets, prompting it to temporarily suspend withdrawals. Initially, the company estimated that about $352 million in assets were affected by the incident.
Despite the passage of time since the attack, Bitget has still not disclosed the amount of assets that have been recovered or frozen. Chen said some assets were frozen with the help of other parties in the industry, but she clarified that the company will announce the total figure only after accurately verifying the quantities.
Bitget had also previously asked THORChain, a protocol for exchanging assets between blockchains, to refuse services to addresses associated with the attack. However, the company emphasized that it does not ask the protocol to stop its network; it only seeks to prevent the transfer of stolen assets. In response, THORChain said it cannot selectively blacklist specific addresses.
Chen said the company understands the technical constraints under which decentralized networks operate, and does not ask any protocol to take actions that are technically impossible.
Regarding the earlier suspicion of a possible link to North Korea, Chen explained that what was initially discussed was based on preliminary indicators that emerged during the investigation, and that these indicators are still being assessed. She added that Mandiant and SlowMist support the independent criminal investigation, and that the work is ongoing, with a commitment to share additional findings once they are verified.
This case highlights the risks of the security supply chain in the digital assets sector, as the danger may not always be within the underlying infrastructure itself, but in external tools and services that are granted sensitive operational permissions. It also underscores the importance of separating privileges, independent verification, and continuous monitoring, as fundamental defensive layers for both companies and users.
#الأمن_السيبراني #العملات_المشفرة $BGB $RUNE
