Why this matters

Bitget’s account of its Sept. 24 breach locates the failure point outside its own custody stack. Cold wallets, where exchanges keep the bulk of customer funds offline, were never touched. Private keys were never exposed. Instead, CEO Gracy Chen said an attacker exploited a zero-day in a third-party security product to pull internal credentials from a management system, then used those credentials to feed fraudulent withdrawal commands into Bitget’s wallet services, which processed them as routine, according to LavX News. That distinction matters for the industry: it shows a vendor integration with access to privileged systems can move real funds without ever touching a signing key.

Key Takeaways

  • Bitget says an attacker used a zero-day in an unnamed third-party security product to obtain internal credentials, not to breach cold wallets or private keys.
  • Two small test transfers at 18:31 UTC on Sept. 24 stayed below Bitget’s risk-control threshold and triggered no alert; larger transfers followed about 30 minutes later.
  • Bitget’s estimate of the loss moved from roughly $351.6 million to about $387.5 million to $388 million after the exchange identified additional Zcash and TRON transfers, which it says reflects more complete accounting, not new theft.
  • Bitcoin withdrawals resumed Monday (Sept. 28), with 9,585 orders totaling 4,098.036 BTC processed as of 17:00 UTC+8; other assets return in phases through Oct. 2.
  • Bitget suspects the same North Korea-linked group it flagged earlier, and blockchain analytics firm TRM Labs found overlaps with wallets tied to prior thefts attributed to TraderTraitor, but neither has made a firm attribution.

How the credentials became a withdrawal path

The mechanism Bitget describes runs through an internal management system rather than the wallet infrastructure itself. Chen said the attacker reached that system through the vendor flaw, then inserted fraudulent withdrawal commands into wallet services from inside, according to LavX News. Because the commands carried valid internal credentials and were disguised as routine administrative activity, Bitget’s infrastructure signed and sent them as if they were legitimate customer withdrawals. Cointelegraph and Crypto Briefing both quote Chen making the same point: the attacker had high-level internal credentials, and private keys were never part of the compromise.

Bitget has not named the vendor or the product. Chen calls the flaw a zero-day, meaning it was exploited before a patch existed, and the exchange said it notified the vendor but hasn’t confirmed a fix is available. Xie Jiayin, Bitget’s Head of Greater China, described the episode in a livestream as a supply-chain attack targeting third-party security software specifically, according to PANews, which frames the incident less as a wallet-security failure and more as a failure in how much trust an integrated vendor product was granted.

Why the risk controls missed it

The attack’s staging exploited a threshold gap rather than a missing control entirely. Bitget said the attacker sent two small test transfers at 18:31 UTC on Sept. 24 that stayed under its risk-control threshold, so no alert fired, per LavX News. Roughly 30 minutes later, larger transfers followed and moved through the same approval path the small transfers had already validated. That sequence, testing thresholds and monitoring before scaling up, is the pattern Bitget is now telling other platforms to specifically test for, along with mapping every vendor connection that touches privileged systems and requiring a separate approval path for high-value transfers.

Bitget’s own loss estimate shifted as tracing continued. The exchange initially put affected assets at about $351.6 million after detecting unauthorized transfers, then raised that to roughly $387.5 million to $388 million once it identified additional Zcash and TRON transfers, a revision it attributes to more complete accounting rather than a second wave of theft, as reported by Crypto Briefing.

Recovery, funding and the THORChain friction

Bitget says the Protection Fund, which covers security incidents, will absorb the loss rather than customer balances. The fund held more than $464 million when the incident was first disclosed, and Chen said Bitget will replenish it with its own capital to bring the value back above $300 million within a week, a level the exchange has historically committed to maintaining; its August report placed the fund’s average monthly value at $382 million, according to Crypto Briefing. Chen also announced “Project Stand Together,” a trading-fee reward pool with added benefits for retail, VIP, professional and market-making users.

Bitcoin withdrawals on the Bitcoin network and BNB Smart Chain resumed at 08:00 UTC Monday after additional security checks, with 9,585 orders totaling 4,098.036 BTC processed as of 17:00 UTC+8, and ether, USDT and other assets set to follow in phases through Oct. 2. On tracing stolen funds, Bitget had asked THORChain, a cross-chain swap protocol, to refuse service to attack-linked addresses. Chen clarified Bitget is not asking THORChain to halt its network, and THORChain has said it cannot selectively blacklist individual addresses, a limitation Chen said Bitget respects, per Cointelegraph.

Attribution and address tracking

Bitget suspects the same North Korea-linked group it referenced immediately after the theft, though Chen has declined to name a specific group ahead of the exchange’s formal incident report. TRM Labs found overlaps between the stolen funds and wallets used in earlier thefts attributed to North Korean operators, linking the activity to TraderTraitor without making a firm attribution, according to LavX News. Bitget published four attacker-linked addresses on Sept. 25, spanning Ethereum and EVM networks, XRP, Zcash and TRON, and set up a live tracking dashboard, asking other exchanges, stablecoin issuers, bridges, custodians and infrastructure providers to monitor them. TRM has advised screening incoming deposits against those tagged addresses and against funds moved through intermediary wallets, since the stolen proceeds passed through bridges and cross-chain swap services that can obscure the original source address.

What to Watch

Bitget plans to publish a formal incident report during the week of Sept. 28, which should name the affected vendor product and clarify whether a patch exists. Non-Bitcoin asset withdrawals are scheduled to restore in stages through Oct. 2, and the Protection Fund’s replenishment to above $300 million is targeted within a week of Chen’s Monday statement. Attribution to a specific group remains unconfirmed pending that report, and it’s unclear how much of the $388 million, if any, has been frozen or recovered through the address-monitoring effort.

Sources