Bitget has given the first concrete root-cause detail on the September 24 breach that cost it approximately $387.5 million: the attacker exploited a vulnerability in a third-party security product to obtain "high-level internal credentials," then used those credentials to issue fraudulent withdrawal commands.
CEO Gracy Chen laid out the mechanism in comments to Cointelegraph, corroborated by Daily Hodl and remarks from her live AMA reported by crypto.news. Bitget's private keys were not compromised and its cold wallets were not affected, she said — consistent with the exchange's earlier statement that the attacker compromised a backend system connected to wallet infrastructure and manipulated the data fed to its authorization process.
Security Tooling as the Entry Point
If the account holds, the breach inverts a familiar assumption: a product deployed to defend the exchange became its point of failure. Rather than defeating key custody, the attacker abused privileged access inside the operational stack — the same attack-the-authorization, not-the-key pattern that produced the February 2025 Bybit theft, as TRM Labs noted in its first reconstruction of the incident.
Bitget says it has since addressed the flaw and tightened withdrawal controls: restricting internal access, adding independent verification for withdrawals, and increasing monitoring for unusual activity.
The exchange has not disclosed how much of the stolen crypto has been recovered or frozen. Chen said some assets have been frozen with help from other industry participants, but that Bitget will publish totals only after verifying the amounts.
Attribution Still Open
Chen also walked back the framing of the exchange's earlier suspicion of North Korean involvement, which had cited IP-based clues. "What was shared previously was based on preliminary indicators identified during the investigation," she told Cointelegraph. "Those indicators are still being assessed. Mandiant and SlowMist are supporting the independent forensic investigation, and that work is ongoing."
North Korean involvement therefore remains suspected and unconfirmed — BleepingComputer continues to describe the actors as suspected North Korean hackers — and any definitive attribution awaits the forensic findings.
Withdrawals Restarting in Phases
Bitcoin withdrawals resumed September 28 on mainnet and BNB Chain, the first step in the staged restart Bitget published: Ether is scheduled for September 29, USDT for September 30, and remaining tokens, fiat and P2P services by October 2.
On THORChain, through which attacker funds have been swapped, Chen struck a softer tone than last week's demand that the protocol block linked addresses: "We respect the technical constraints of different networks and are not asking any protocol to take actions that are not technically possible," she said. THORChain maintains it cannot selectively blacklist addresses.
The disclosure leaves two open questions for the post-mortem record: which third-party product failed, and whether the vendor chain around a core exchange — multiple security products holding privileged positions — gets the same scrutiny as the exchanges themselves.
TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.